m'M 


The  Magazine  for  Information  Executives 


Need  managed 


Imagine  having  all  the  world’s  best  e-business  protection  at  your  beck  and  call.  24/7.  Now  you  can  have  managed  network 
security  and  availability  services  via  the  Internet  with  myCIO.com,  the  world's  first  infrastructure  application  service  provider 
(ASP).  It  features  services  built  on  the  world’s  leading  products  like  McAfee,  PGP  and  CyberCop.  So  myCIO.com  is  continuously 

on  the  job,  defending  your  company  against  the  many  threats  you  face  from  both  inside  and  out. 

Visit  myCIO.com  today  for  a  FREE  30-day  trial  of  managed  security.  Then  sign  up  for  a  little  peace  of  mind 


security 


anti-virus 
security  audits 

firewall 

VPN 

insomnia 

budgets 

sanity? 


Q 


myCIO.com 


Your  Chief  Internet  Officer 


Here’s  to  a  faster 
Web  site:  the 
Compaq  TaskSmart 
C-Series  server. 


©2000  Compaq  Computer  Corporation.  Compaq,  the  Compaq  logo  and  NonStop  are  registered  in  U.S.  Patent  and  Trademark  Office.  TaskSmart  is  a  trademark  of  Compaq  Information  Technologies  Group,  L.P. 


GOOD  IS 


ONDIRFUL  CONTEN 

IF  NO  ONE  CAN  GET  TO  IT 

TASKSMART  SERVERS  FOR  INTERNET 
CACHING:  FASTER  WER  ACCESS  FOR  ALL 

Is  your  Web  site  a  victim  of  its  own  success?  Clogged  with  traffic  from 
•the  customers,  vendors  and  employees  it  was  designed  to  serve? 

i  '  i 

Easy  fix:  the  Compaq  TaskSmart  C-Series  server.  It  un-bottlenecks 
Web  access  by  allowing  more  browser  connections,  and  serving 

I 

frequently  accessed  content  from  a  high-speed  cache.  Translation: 
it’s  way  fast.  You  get  more  capacity.  Better  peak-load  handling.  And 
it  installs  in  as  little  as  15  minutes,  no  PhD  required.  A  NonStop ™ 

eBusiness  Solution  for  virtually  any  Web  site:  who  wouldn’t  drink  to 

»  i 

that?  Details:  www. co mpa q . co m/ta sks ma rt . 

24xJx  COMPAQ 


COMPAQ.  NonStop 


The  Cajun  P33CT 
is  a  10/100/1000 
Ethernet  switching 
system  (stack  up 
to  10,  scale  up  to 
640  ports). 


Can-Do! 

stackable 
switching  system 


the  Cajun  P330  can  do  everything  a  modular  switch 

does. ..and  can  do  it  at  half  the  price! 

Lucent's  Cajun  P330  “  can  do  multi-service 
applications  (right  out  of  the  box). 

Resilient  like  a  modular  switch  (without 
the  big  price  tag),  it  grows  right  along 
with  your  business.  So  the  more  you 
need  it  to  do,  the  more  it  can-do!  What's 
more,  it’s  easy  to  get  running  (and  it 
keeps  running)  without  a  big  to-do.  Go  to 
www.lucent.com/ins/can-do  (info-central 
for  special  promotions)  to  see  how  the 
Cajun  P330  stacks  up.  It's  the  stackable 
that  can-do!  it  all. 

We  make  the  things  that 
make  communications  work." 


Inside 

VOL.  13  •  NO.  16  •  JUNE  1,  2000 

Features 

Pro  and  Con  72 

COVER  STORY:  SECURITY  What  do  you  get  when  you  hire  a 
hacker  to  solve  your  security  woes?  If  you’re  not  careful,  you 
can  get  more  than  you  bargained  for  Here’s  how  to  do  it 
right.  By  Daintry  Duffy 

ERP  Training  Stinks  86 

ENTERPRISE  SYSTEMS  As  ERP  implementations  falter  and 
fail,  many  people  think  the  answer  is  more  training.  They’re 
wrong.  By  Malcolm  Wheatley 

How  I  Survived  My  IPO  98 

WEB  BUSINESS  Is  the  grass  really  greener  on  the  other 
side  of  the  IPO?  These  three  companies  are  finding  out. 

By  Beth  Stackpole 

Emancipation  Proclamation  112 

INTERVIEW:  STEVE  BALDWIN  AND  BILL  LESSARD  The  authors 
of  Net  Slaves  pay  tribute  to  the  unheralded  victims  of  the 
dotcom  revolution.  By  Meg  Mitchell 

Built  to  Move  120 

I.T.  ARCHITECTURE  E-commerce  is  changing  how  IT  plans 
and  builds  systems.  Command  and  control  are  out;  flexibility 
and  collaboration  are  in.  By  Constantine  von  Hoffman 


Ex-hacker  Brian  Martin  advises  CIOs  to  get 
to  know  their  security  consultants.  72 


Free  to  Be  130 

MERGERS  &  ACQUISITIONS  For  Lycos,  the  best  way  to 
integrate  new  companies  under  its  corporate  umbrella  is  to 
help  them  remain  autonomous.  By  Stewart  Deck 

Controlled  Substances  140 

ASSET  MANAGEMENT  Keeping  tabs  on  all  your  IT  assets 
may  seem  nearly  impossible,  but  a  formal  approach  and 
the  right  systems  can  make  it  pay.  By  Karen  D.  Schwartz 

Knowledge  Fusion  152 

CASE  FILES  How  the  Tennessee  Valley  Authority’s  nuclear 
division  saved  time  and  money  by  integrating  machine- 
maintenance  knowledge  and  workflow  processes. 

By  Carol  Hildebrand 

Chaos  Control  156 

BOOK  EXCERPT:  HARNESSING  COMPLEXITY  As  Linux 
demonstrates,  one  way  to  ensure  coherence  in  a  complex 
world  is  to  encourage  variety.  By  Robert  Axelrod  and 
Michael  D.  Cohen 


MORE  ►  ►  ► 


Cover  photo  by  Michael  Kelley 


6 


CIO  JUNE  1,  2000  •  www.cio.com 


(Computer 


It 

* W lx!r%rl *  W  S 

When  we  say  Unicenter®  can  manage 
anything,  anywhere,  we  mean  it. 

As  this  Formula  One  MP4/14  car 
races  along  at  speeds  in  excess  of  210 
miles  per  hour,  pulling  G  forces  that  rival 
a  jet  fighter  plane,  it  broadcasts  hun¬ 
dreds  of  megabytes  of  critical  telemetry 
data  back  to  the  pit  crew.  They  use  it  to 
make  split-second  decisions  that  often 
mean  the  difference  between  victory 
and  defeat. 

Unicenter  TNG®  helps  the  West  McLaren  Mercedes  race 
team — one  of  the  winningest  teams  in  Formula  One  history — 
interpret  this  vital  information  through  Unicenter  TNG’s  sophisti¬ 
cated  manager/agent  technology,  and  a  revolutionary  3-D 
interface.  Everything  that’s  happening,  from  the  pressure  on 


the  left  rear  brake  pad  to  the  downforce 
of  the  chassis  set-up,  can  be  monitored 
and  managed  through  Unicenter  TNG. 

By  looking  at  this  data  in  a  whole 
new  way,  the  West  McLaren  Mercedes 
race  team  can  now  make  smarter 
decisions  in  less  time.  In  a  business 
where  hundredths  of  a  second  can 
mean  the  world,  Unicenter  TNG  is 
making  a  difference. 

This  is  just  one  example  of  how 
Unicenter  TNG  today  is  managing  all  kinds  of  non-IT  devices 
for  all  kinds  of  organizations. 

Call  us  to  find  out  how  Unicenter  TNG  can  help  you 
be  more  competitive. 

Call  1-888-UNICENTER,  or  visit  www.cai.com 


Unicenter  TNG’s  Real  World  Interface ™  analyzes  critical 
performance  measures  such  as  front  and  rear  brake 
pressure  impact  on  car  speed. 


(Computer® 

Associates 

Software  superior  by  design. 


Ilnicenter  IHG* 


©1 997-1 999  Computer  Associates  International,  Inc.,  Islandia,  NY  1 1 749.  All  product  names  referenced  herein  are  trademarks  of  their  respective  companies. 


►  explosive  denial  of  service  threats 


►spiraling  end-user  service  demands 


you  never  know 


your  e-busines< 
will,  come  from 


►  drowning  in  unanticipated  traffic 


i 


crazy  out  there.  But  here’s  how  to  keep  your  mental  health: 
Concord’s  e  Health™  solution  suite. 

Building  on  the  success  of  our  Network  Health®  product,  Concord’s 
e  Health  consists  of  fully  integrated  best-of-breed  products  that 
measure,  monitor,  and  proactively  manage  potential  threats  to  your 
e-business,  e Health  provides  early  and  detailed  alerts,  scales  easily 
to  meet  ever-changing  business  needs,  and  quickly  integrates  into 
your  existing  technology  infrastructure. 

To  succeed  in  e-business,  you  have  to  anticipate  the  unexpected. 
Get  all  the  help  you  can:  Concord’s  e  Health. 


Find  out  more  at  www.concord.com  or  call  800-851-8725. 


►  looming  24x7  obstacles  to  availability 


Inside 

Columns 

Steppin’  Out  52 

CAREER  COUNSEL  Mark  Polansky 
offers  advice  to  aspiring  CIOs  and 
IT  managers. 

The  Winner’s  Circle  60 

DAVENPORT  If  you  want  your  e-strategy 
to  succeed,  you’d  better  figure  out 
what  you  want  to  be. 

By  Tom  Davenport 

Inspiring  Minds  66 

TOTAL  LEADERSHIP  Part  of  being  a  great 
leader  is  finding  ways  to  inspire  those 
around  you.  By  Patricia  Wallington 

Jose-Marie  Griffiths  200 

INTERVIEW  The  role  of  the  librarian 
in  the  digital  age.  By  Cheryl  Bentsen 


182 


Opinion 

Private  Matters  178 

DIFFERENCE  ENGINE  Could  your  organi¬ 
zation’s  privacy  practices  stand  the 
scrutiny  of  a  newspaper  expose? 

By  Simson  L.  Garfinkel 

Why  Are  We  Protecting 
the  Software  Industry?  182 

SOUND  OFF  Taking  sides  on  critical  issues. 

By  Martha  Heller 

Meeting  of  the  Minds  186 

PLATFORM  Learn  decision-making  skills 
to  ensure  your  company’s  success. 

By  Tom  Murphy 

Real-Time  Angst  188 

REALITY  BYTES  Too  much  access  to 
information  can  make  even  the  sanest 
person  a  little  twitchy.  By  Megan  Santosus 


In  Every  Issue 

From  the  Editor 

By  Abbie  Lundberg 

l8 

InBox 

Reader  feedback 

22 

Trendlines 

30 

BY  THE  NUMBERS 

Enterprise  application  projects 
Compiled  by  Derek  Slater 

34 

ON  THE  MOVE 

Rubin  retires  from  Elf  Atochem 
Compiled  by  Tom  Field 

46 

Emerging  Technology  164 

A  new  crop  of  unnaturally  born 
killers  targets  networked  computers. 

By  John  Edwards 

REVISIT 

POS  scanners 

170 

PREDICTIONS 

E-commerce  software 

174 

UNDER  DEVELOPMENT 

Flat-panel  screens 

176 

Index 

I98 

Reading  Is 

Fundamental  192 

FROM  THE  PUBLISHER  The  education  and 
importance  of  people  in  every  economy. 

By  Gary  Beach 


“One  of  the  best  w  ays  to  become  an  inspirational 
leader  is  to  study  those  who  are.  Better  yet, 

work  for  one  and  learn  from  her.”  -Patricia  Wallington  66 


10  CIO  JUNE  1,  2000  •  www.cio.com 


<z>  C0R10 

APPLICATIONS  ON  DEMAND 


MOAI 


# Sun 

microsystems 
We’re  the  dot  m  .corrr 


George  Bell,  President,  Excite@Home 


do 


Broad  Vision 

Ptersonalitiitg  c  -Business* 


COMMERCE  <^s 
0NE.s 


How 


Call  CORIO  at  877.267.4627 
or  visit  www.corio.com 


Microsoft 


Excite@Home  knew  they  would 
need  top  tier  business  applications 
to  manage  their  rapid  growth. 
They  hired  Corio.  Corio  hosts  leading 
applications  covering  e-Commerce, 
Customer  Relationship  Management 
and  ERP— all  fully  integrated.  Simply 
access  any  of  these  applications 
over  a  secure  network  for  a  monthly 
fee.  Lower  total  cost  of  ownership. 
No  IT  worries.  Like  Excite@Home, 
focus  on  your  core  business— and 
let  Corio  do  the  rest. 


Get  this  IDC  written 
white  paper  FREE! 


we  manage  our  growth? 

hired  Corio. 


©  2000  Corio,  Inc.  All  rights  reserved.  All  other  company  and  product  names  are  trademarks  of  their  respective  owners. 


That  great  plan  for  a  business  you've  been  saving? 

It's  time  to  let  it  out  into  the  world.  Because  now  everyone  can 
play  in  the  emerging  e-services  economy.  Your  rainy  day  idea 
can  team  up  with  someone  else's  rainy  day  idea,  or  everyone  else's 
rainy  day  idea.  And  hp  servers,  storage,  software  and  consulting 
will  help  tie  them  all  together.  Do  you  have  a  business  in  you? 
Invent  it  here:  www.hp.com/e-services 

The  Grand  Opening  of  You. 
e-services  solutions  from  hp. 


invent 


On  CIO.com 


Should  IT  Professionals  Be 
in  the  Ethics  Business? 

SOUND  OFF  With  direct  access  to  sensitive  data,  IT  workers 
are  confronted  daily  with  ethical  decisions, 
but  they  have  little  in  the  way  of  ethics 
training.  Should  they  hand  over  tough 
decisions  to  HR  or  learn  how  to  handle 
them?  Join  the  debate,  comment.cio.com 

Mentors  Wanted 

MENTOR-MATCHING  SERVICE  CJO’s  new  service  connects 
mentors  with  IS  managers  looking  for  leadership  counsel. 
Veterans,  share  your  hard-earned  insight  with  next- 
generation  CIOs  and  give  something  back  to  your  profes¬ 
sion.  You’ll  be  a  better  manager  for  it.  Contact  Senior 
Executive  Editor  Richard  Pastore  at  pastore@cio.com. 

The  Seamy  Side  of  IT 

CIO  RADIO  Steve  Baldwin  and  Bill  Lessard,  coauthors  of 
Net  Slaves:  True  Tales  of  Working  the  Web  (McGraw-Hill, 
1999),  debunk  the  rags  to  riches  myth  of  the  high-tech 
industry.  (Coming  June  7.)  www.cio.com/radio 


Featured  This  Month 

WHAT  IS  A  B-WEB?  Chances  are,  you’re 
already  a  part  of  one,  so  you’d  better  brush  up 
on  the  rules.  From  June  1  to  June  30,  CIO’s 
Reading  Room  will  feature  an  Ask  the  Author 
appearance  by  Don  Tapscott,  David  Ticoll  and 
Alex  Lowy,  authors  of  Digital  Capital:  Harness¬ 
ing  the  Power  of  Business  Webs  (Harvard 
Business  School  Press,  2000).  Read  an 
excerpt  from  the  book  and  pose  questions  to 
the  authors,  www.cio.com/books 


“Its  not  easy  turning  in 
your  boss  or  coworkers, 
but  it  saves  the  company 
headaches  down 
the  road.” 

-A  reader  responding  to  Sound  Off, 
“What  Should  You  Do  with  Illicit 
Information  You  Find  on  the  Job?” 

comment.cio.com 


The  Check’s  in  the  E-mail 

ASK  THE  EXPERT  Have  a  question  about  electronic  bill 
presentment  and  payment?  From  June  1  to  June  15, 

Darryl  Dobin,  executive  vice  president  and  chief  marketing 
officer  for  San  Francisco-based  Just  in  Time  Solutions, 
will  offer  insight  into  the  internet  billing  standards  debate 
and  advice  on  choosing  an  online  billing  solution. 
www.  do.  com/ Cl  O /expert 

You’ve  Got  Two  Weeks 

ENTERPRISE  VALUE  AWARDS  The  deadline  for  applications, 
which  you  can  find  online,  is  June  15.  If  your  IT  department 
delivers  lasting  value  to  the  enterprise,  tell  us  about  it. 
Winners  will  be  profiled  in  the  Feb.  1,  2000,  issue  of  CIO 
and  honored  at  an  awards  ceremony  in  Tucson,  Ariz. 
www. cio.com/eva 

Tell  Me  Something  I  Don’t  Know 

ANALYST  CORNER  The  latest  research  on  ASPs,  IT  perfor¬ 
mance  and  more,  www.cio.com/analyst 

Extra,  Extra 

CIO  INSIDER  We’ll  fill  you  in  on  the  latest  from  CIO.com. 
Sign  up  for  your  e-mail  newsletter  today. 
www.cio.com/CIO/cioinsider.html 


14  CIO  JUNE  1,  2000  •  www.cio.com 


Database 

Microsoft  or  Oracle 

Marketing 

Epiphany  or  Oracle 

Sales 

Siebel  or  Oracle 

Webstore 

IBM  or  Oracle 

Procurement 

Commerce  One  or  Oracle 

Manufacturing 

SAP  or  Oracle 

Supply  Chain  Mgmt 

i2  or  Oracle 

Financials 

SAP  or  Oracle 

Human  Resources 

PeopleSoft  or  Oracle 

Support 

Clarify  or  Oracle 

Get  a  complete 
e-business  suite 
from  Oracle. 


Or  assemble 
software  from 
10  different  vendors 
(no  instructions  included). 

The  choice  is  yours. 


SOFTWARE  POWERS  THE  INTERNET 


©2000  Oracle  Corporation.  All  rights  reserved.  Oracle  and  Software  Powers  the  Internet  are  registered 
trademarks  of  Oracle  Corporation.  Other  names  may  be  trademarks  of  their  respective  owners. 


www.oracle.com 


Curious  term,  this  “generation  d  ”  This  new  digital  generation. 

This  is  a  generation  that’s  as  comfortable  sitting  in  front  of  a 
computer  screen  as  a  television  screen. 

This  is  a  generation  that  embraces  Wireless,  DSL  and  VPN 
as  natural  additions  to  the  world  of  Frame  Relay,  ATM  and  the 
Internet.  This  is  a  generation  that’s  turning  brick-and-mortar 
businesses  into  click-and-mortar  ones.  And  in  doing  so,  turning 
the  old  economy  into  the  new  e-conomy. 

This  is  a  generation  that  has  found  a  home  at  WorldCom?" 
A  company  of  generation  d,  by  generation  d  and  for  generation  d. 

For  more  details,  visit  us  at  www.wcom.com/generationd. 


•V  -^7/ 

■  ■'  .fil'  ». 


. 


generation  d 


From  the  Editor 

lundberg@cio.com 


In  Sync 

You  never  know  where  you’re  going  to  find  inspiration. 

Friday  night  was  Lip  Sync  night  at  my  kids’  elementary 
school.  This  is  an  annual  event  put  on  by  the  fifth-graders 
and  some  of  the  more  extroverted  teachers  and  administra¬ 
tors.  The  kids  spent  the  last  two  or  three  weeks  choosing 
songs,  learning  the  music,  arranging  dance  moves,  planning 
costumes  and  getting  together  with  their  fellow  performers 
to  rehearse.  My  daughter  and  two  of  her  pals  performed 
Randy  Newman’s  “You’ve  Got  a  Friend  in  Me,”  the  theme 
song  from  Toy  Story.  My  favorite  performance  was  a  ren¬ 
dition  of  “The  Saga  Begins,”  Weird  A1  Yankovic’s  reworking 
of  Star  Wars:  The  Phantom  Menace  set  to  the  tune  of  Don 
McLean’s  “American  Pie”  (check  it  out  at  wivw.sagabegins. 
com).  But  the  performance  I’d  been  hearing  the  most  about 
since  rehearsals  began  was  “Stayin’  Alive,”  from  the  movie 
Saturday  Night  Fever.  According  to  the  kids,  it  was  going 
to  be  awesome. 

But  something  happened.  On  Thursday,  the  three  boys 
doing  “Stayin’  Alive”  (I’ll  call  them  Luke,  Pete  and  Benny) 
were  in  the  boy’s  room  changing  for  the  dress  rehearsal. 
Pete  and  Benny  ask  Luke,  by  far  the  smallest  of  the  three, 
where  he  got  his  costume.  Luke  tells  them  he  borrowed  it 


from  a  friend — who  happens  to  be  a  girl.  Pete  and  Benny  think 
this  is  a  riot  and  start  teasing  Luke.  The  teasing  escalates  and 
things  get  rough;  Luke  doesn’t  stand  a  chance.  Teachers  find 
out,  and  Pete  and  Benny  are  banned  from  Lip  Sync  night.  So 
not  only  do  Luke’s  friends  turn  on  him,  but  this  thing  he’s  been 
working  toward  for  weeks  is  ruined. 

Only  it  wasn’t.  “Staying  Alive”  is  the  last  piece  of  the  night. 
We  know  at  this  point  that  Pete  and  Benny  are  out,  and  assume 
it  will  be  cancelled.  But  no,  the  song’s  announced,  and  on 
comes  Luke — all  by  himself.  The  music  starts,  the  spotlight 
hits  him,  and  I’ll  tell  you,  you’ve  never  seen  a  more  enthusiastic, 
committed  disco  dancer.  The  kid  puts  his  heart  and  soul  into 
this  five  minutes  like  nothing  else  matters  in  the  world.  The 
rest  of  the  kids  go  wild,  yelling,  “Go  Luke!”  in  unison  at  well- 
placed  breaks  in  the  music.  I  am  moved  by  Luke’s  courage  and 
determination  and  also  by  the  support  shown  him  by  the  rest  of 
the  kids. 

I  don’t  know  what  Luke  will  take  away  from  this  experi¬ 
ence,  but  I  know  I’ll  think  of  him  the  next  time  something 
discouraging  gets  in  my  way.  Sometimes  inspiration  comes 
from  unusual  places. 


18  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  FURNALD/GRAY 


Focuse 


,  on  data  from  day  one  •  Serving  business  customers  only  .  #]  ratecf  lnferne( 

•  Frame  Relay/ATM  network  running  at  99.999%  reliability  b< 


CONFIDENCE 

THUMBS-UP 

FOR  INTERMEDIA'S 

QUALITY 

&  SERVICE! 


www.  intermedia. 


com 


boardwatch 


#1  rated  Internet  backbone,  Boardwatch  magazine  1999 


#1  rated  Managed  Security,  Network  Computing  magazine  1998 
#1  rated  overall  ISP  TeleChoice  survey  1999,  and  #1  in  customer  service  1998 


Pinnacle  Award  winner  for  service  and  innovation,  X-Change  and  Phone+  magazines 


Top  25  ISP,  Data  Communications  magazine  1 999  and  1 998 
"Dynamic  1 00"  Top  Technology  Company  rankings,  Forbes  ASAP  magazine  1 999  and  1 998 


1 


Top  1 00  Growth  Company  and  "Hot  Growth  Company,"  Network  World  magazine  1 999 


Now  that's  confidence. 


INTERNET  LOCAL/LONGDISTANCE  PHONE  800-250-2222  NASDAQ 


ICIX 


Connect  with  Confidence 

2000  Intermedia  Communications  Inc,  All  rights  reserved.  Intermedia  Communications,  the  Intermedia  logo,  and 
Connect  with  Confidence  are  trademarks  of  Intermedia  Communications  Inc.  All  other  trademarks  used  herein  are  the 
property  of  their  respective  owners.  Network  reliability  is  based  on  internal  network  reports  for  01  &  Q2  of  1999. 


SM 


intermedia 


COMMUNICATIONS 


wwn 


©  2000  Research  In  Motion  Limited  All  rights  reserved 
BlacKBerry  is  an  end-to-end  wireless  email  solution  developed 
by  Research  In  Motion  (RIM).  BlackBerry,  the  BlackBerry  logo, 
RIM.  RIM  950  Wireless  Handheld.  RIM  957  Wireless  Handheld 
and  the  “envelope  in  motion"  symbol  are  trademarks  of  RIM 


NNECTED. 


You’re  probably  bombarded  by  demands  for  wireless  ‘connectivity’  these  days.  But  let’s  face  it  - 
there’s  been  a  shortage  of  viable  solutions  to  satisfy  these  needs  and  your  concerns.  Introducing 
BlackBerry™  -  the  wireless  email  solution  designed  for  business.  It’s  the  only  totally  integrated 
package  that  includes  handhelds,  desktop  tools,  server  software  and  flat-rate  airtime. 
No  more  dialing-in,  no  secondary  mailboxes  and  no  worries.  Mobile  employees  get  secure  email 
while  IT  gets  centralized  administration  and  control.  BlackBerry  wireless  email  -  it’s  the  best  of 
both  worlds. 


Product  of  the  Year  -  BlackBerry  wins  hands  down  when  it  comes  to  easy 
and  timely  access  to  email  messages.  It  provides  a  lightweight,  always-on  solution  at  a  low 
cost,  appropriate  even  for  users  with  the  fewest  technical  skills.**  INFOWORLD 


RIM  950  WIRELESS  HANDHELD'" 


www.blackberry.NET 

|[\|  pO@BLACKBERRY.NET 


BLACKBERRY 


WIRELESS  EMAIL  SOLUTION 


InBox 

Reader  Feedback 


FURNITURE. COM'S  GUARANTEE 

In  the  Jan.  15,  2000,  issue  of  CIO,  the  “Furniture.com”  case  file  and  the  accompanying 
analysis  criticized  the  company’s  policy  of  allowing  consumers  only  exchanges  or  store 
credit  for  returned  items. 

While  that  was  the  policy  at  the  time  the  article  was  written,  Furniture.com  in  January 
instituted  a  significant  change  in  its  return  policy— a  30-day,  no  questions  asked,  money- 
back,  customer  satisfaction  guarantee.  Under  the  new  policy,  customers  can  live  with  a 
purchase  for  a  month  and  decide  if  it’s  right.  If  a  shopper  is  unhappy  for  any  reason, 
design  consultants  will  assist  with  a  new  selection— or  arrange  a  full  refund  and  return  of 
the  item,  with  no  restocking,  handling  or  return  shipping  charges. 

We  believe  our  new  guarantee  is  more  in  line  with  our  commitment  to  provide 
consumers  with  the  best  home  furnishings  and  decorating  experience. 

Don  Goncalves  •  Director  of  Public  and  Investor  Relations  •  Furniture.com 

•  Framingham,  Mass.  •  dgoncalves@furniture.com 


THREE  CHEERS  FOR 
CLEAR  THINKING 

Thanks  for  seeing  through  the  smoke 
of  battle  and  calling  things  like  they 
really  are.  Two  commentaries  stood 
out  in  the  March  1,  2000,  issue.  Com¬ 
bined  with  “E-Nuf  Already,”  your 
editor’s  letter  “Pushing  the  E-Panic 
Button”  was  among  the  first  clearly 
stated,  clearly  considered  comments 
on  the  state  of  IS-IT  and  business 
planning-management  I’ve  seen  since 
the  world  began  to  lose  its  mind  with 


internet  mania.  The 
balance  you  speak  of, 
“nimble  strategies” 
versus  “panic  instead 
of  strategy,”  is  pre¬ 
cisely  what’s  called  for. 

While  lumbering 
strategies  that  center 
on  denial  of  the 
changes  that  sur¬ 
round  us  will  clearly 
be  self-exterminating, 
so  too  will  be  those 
reactions  to  the  current  level  of  change 
that  assume  that  visioning,  planning  and 
managing  are  things  of  the  past. 

Thanks  for  reminding  those  of  us 
who  believe  as  you  do  that  we’re  not 
quite  as  alone  as  we  sometimes  think. 

Justin  T.  Donie 
Cincinnati 

E-LEARNING  UNBOUND 

“Learning  Unbound”  [CIO,  March 
15,  2000]  presented  many  innovative 
approaches  to  corporate  training  and 
made  the  important  point  that  learn¬ 
ing  occurs  through  employee-initiated 


programs,  seminars  and  informal 
interactions. 

However,  I  felt  the  article  was  miss¬ 
ing  a  presentation  of  e-learning  inno¬ 
vations,  for  example,  utilizing  the 
internet  for  courses,  training,  seminars 
and  informal  communication.  There 
is  a  wide  range  of  technologies,  vary¬ 
ing  in  sophistication  and  capabilities, 
that  are  used  successfully  within  many 
corporations. 

In  my  experience,  I’ve  seen  that  not 
only  can  effective  learning  and  training 
occur,  but  there  are  side  benefits,  such 
as  the  creation  of  virtual  communities 
and  the  development  of  greater  tech¬ 
nology  literacy,  resulting  from  introduc¬ 
tion  to  and  use  of  technology. 

Lisa  Neal 

Senior  Research  Engineer 
EDS  Web  Universities  and  Training 
Lexington,  Mass, 
lisa.  neal@eds.  com 


EDS  IS  A-OK 

In  reflecting  upon  the  March  15,  2000, 
article  “Insurer,  Heal  Thyself,”  I  find 
myself  less  than  pleased  with  the  char¬ 
acterizations  of  Blue  Cross  and  Blue 
Shield  of  Massachusetts  (BCBSMA). 
Since  I  was  interviewed  for  this  article, 
I  bear  some  responsibility  for  its  tone. 

BCBSMA  is  made  up  of  individuals 
who  are  singularly  focused  on  making 
it  one  of  the  best  companies  in  America. 
The  people  who  work  here  are  all  ded¬ 
icated  to  providing  our  health-care 
members  and  the  health-care  profes¬ 
sionals  who  care  for  them  with  the 
highest-quality  service.  In  the  technol¬ 
ogy  division  for  which  I  have  responsi¬ 
bility,  the  associates  bring  a  unified 
determination  to  their  job  every  day. 


22  CIO  JUNE  1,  2000  •  www.cio.com 


WHY  FIKIMAIR  IS  GOING  WITH  OUR  E-BUSI IM  ESS  SOLUTIONS 

“"  “LONG  HAUL 


When  Finland's  national  airline  was 
looking  to  lift  long-distance  cargo  sales, 
it  looked  to  e-business  technology.  And 
that  meant  Unisys.  Our  solution?  The 
Unisys  e-@ction  Internet  Commerce 
Enabler:  A  unique  application  that 


05134 


allows  Finnair's  partners  and  clients  to 
place  orders  and  track  cargo  status  and 
location  via  the  Internet.  What's  more,  we 
integrated  this  e-business  solution  into 
Finnair's  existing  systems.  So  the  airline's 
Web-enabled  cargo  operation  could  be 
up  and  flying  quickly  and  economically. 
All  of  which  puts  Finnair  miles  ahead  of 
the  competition.  But  that's  what  you'd 
expect  from  the  people  who  are  always 
ready  to  go  the  distance  for  their  clients. 
www.unisys.com 


UNiSYS 

We  eat,  sleep  and  drink  this  stuff. 


©2000  Unisys  Corporation  Unisys  is  a  registered  trademark  and  e^gction  is  a  trademark  of  Unisys  Corporation 


InBox 


Our  shared  goal  is  to  make  technology 
fulfill  the  company’s  vision  for  service 
excellence. 

EDS  is  our  partner  in  that  goal.  EDS 
is  a  great  partner.  As  a  company,  it  is  a 
tough  negotiator.  But  EDS  is  also  an 
organization  of  professionals  with 
whom  I  am  proud  to  walk  through  the 
business  challenges  we  face  every  day. 

Mark  Caron 
Senior  Vice  President  and  CIO 
Corporate  Information  Systems 
Blue  Cross  and  Blue  Shield 
of  Massachusetts 
Boston 


A  COMMON  GOAL 

I  agree  with  the  publisher’s  opinion 
expressed  in  “A  New  Mandate”  in  the 
April  1,  2000,  issue.  I  am  the  CIO  of  a 
small  company  in  Virginia  that  focuses 
on  database-driven  internet  develop¬ 
ment.  We  have  tried  to  accommodate 
the  preferences  of  new  employees  when 
equipping  their  offices  because  we 
believe  it  will  increase  productivity  and 
job  satisfaction.  It  was  difficult  enough 
to  deal  with  the  Windows-Macintosh 
debate;  now  we  have  Linux  joining  the 
fray  as  well.  Each  of  these  has  its  own 
merits,  but  it  becomes  increasingly  com¬ 
plex  to  provide  companywide  network¬ 
ing  services  to  each  user  as  new  operat¬ 
ing  systems  and  versions  of  that  oper¬ 
ating  system  are  placed  on  our  LAN. 

Driven  by  this  problem  of  platform- 
dependent  networking  utilities,  I  believe 
that  the  various  types  of  PC  are  going 
to  be  forced  toward  a  uniform  point.  I 


hope  that  at  some  date  in  the  near 
future,  the  platform  running  the 
machine  will  become  completely  trans¬ 
parent  to  the  network  architecture, 
turning  the  modern-day  PC  into  some¬ 
thing  better  described  as  a  network 
interface  device. 

This  would  also,  as  your  article  sug¬ 
gested,  make  the  machine  itself  of  much 
less  importance  to  anyone  other  than 
the  end  user.  No  longer  will  we  need  to 
configure  and  run  Samba,  AppleTalk, 
NFS  or  the  full  gamut  of  other  pro¬ 
grams  needed  to  make  a  companywide 
network  efficient.  This  is  not  to  say  that 
the  user  interfaces  need  to  become  iden¬ 


tical,  but  beyond  the  network  card, 
device  A  should  not  appear  any  differ¬ 
ent  from  device  B. 

I’d  love  to  see  an  article  on  how  we 
can  reach  that  goal  in  an  industry  still 
focused  on  developing  proprietary 
products. 

Steve  Higgins 

Information  Officer 
NightLight  Design 
www.nldesign.com 
Harrisonburg,  Va. 
steve@nldesign.  com 

NO  FOOLING 

I  usually  make  a  cursory  pass  through 
my  new  CIO  each  month  and  then 
make  a  mental  note  of  the  articles  I 
want  to  read.  But,  when  I  hit  page  46  of 
the  April  1,  2000,  issue,  I  stopped. 
Under  a  banner  that  read  “Robots” 
and  a  headline  “Of  Purrs  and  Grrrs”  is 
a  picture  of  what  appears  to  be  two 


robotic  dinosaurs. ..well,  copulating. 

The  thought  “now  we’ve  gone  too 
far”  whizzed  through  my  head.  And  of 
course,  I  read  the  well-written  and 
informative  article  front  to  back.  No 
robotic  dinos  copulating  (they  are 
standing  side  by  side  if  you  look  real 
close).  So  I  have  to  wonder  if  this  sub¬ 
liminal  suggestion  was  intentional? 
April  Fools,  perhaps? 

I  guess  it’s  comforting  to  realize  that 
sex,  even  clickity  clackity  old  robotic 
dino  sex,  still  sells,  huh? 

Gordon  Peterson 
Technical  Account  Manager 
IDX  Corp. 

Worcester,  Mass. 
gordon_peterson@idx.com 

We’re  impressed  with  your  active  imag¬ 
ination.  However,  we  doubt  the  pho¬ 
tographer  shot  the  photo  with  a  sexual 
connotation  in  mind.  And  knowing 
how  costly  these  robots  are  to  build, 
natural  reproduction  is  probably  pre¬ 
ferred.  -The  Design  Staff 

When  I  saw  your  article  on  the  new 
Techno  Bra  [“Cross  Your  Heart,” 
Trendlines,  CIO,  April  1,  2000],  I 
couldn’t  help  but  think  of  George 
Plimpton’s  farce  in  the  April  1  Sports 
Illustrated  of  years  ago  in  which  we 
learned  of  Sidd  Finch,  the  phenom 
pitcher  whose  fastball  exceeded  120 
mph. 

Real  or  fictional,  the  product  infor¬ 
mation  was  good  for  a  laugh. 

Gary  Abram 

Executive  Vice  President-Development 
Eagle  Global  Logistics 
Houston 
gabram@eagleusa.com 

WHAT  DO  YOU  THINK? 

Send  your  thoughts  and  feedback 
to  letters@cio.com.  Letters  may  be 
edited  for  length  or  clarity. 


mark.  caron@bcbsma.  com 

It  becomes  increasingly  complex  to  provide 
companywide  networking  services  to  each  user 
as  new  operating  systems  and  versions  of 
that  operating  system  are  placed  on  our  LAN. 


2  4 


CIO  JUNE  1,  2000  •  www.cio.com 


If  your  company  is  migrating  to  Windows  2000, 
remember  that  New  Horizons  does  more  Microsoft  technical  training 
and  certification  than  any  other  company. 


Call  1-800-PC-LEARN  today. 

Or  visit  newhorizons.com  on  the  Web. 


New  Horizons' 

Computer  Learning  Centers 

World  leader  in  computer  training. 


©2000  New! 


ffputer  Learning  Centers,  Inc.  /  New  Horizons  is  a  registered  trademark  of  New  Horizons  Education  Corporation. 


©  CIO  Communications  Inc. 


President  &  CEO  Joseph  L.  Levy 
Publisher  Gary  J.  Beach 
Editorial  Director  Lew  McCreary 

EDITORIAL 

Editor  in  Chief  Abbie  Lundberg 

Senior  Executive  Editor  Richard  Pastore 

Managing  Editor  David  Rosenbaum 

Managing  Editor,  Darwin  Elaine  M.  Cummings 

Managing  Editor,  Production  Cheryl  R.  Asselin 

Executive  Editors  Christopher  Koch 
(Investigations),  Derek  Slater 

Technology  Editor  Chris  Lindquist 

Senior  Editors  Todd  Datz,  Alice  Dragoon,  Tom 
Field,  Michael  Goldberg,  Carol  Hildebrand, 

Sari  Kalin,  Megan  Santosus  (Opinion) 

Features  Editors  Sandy  Kendall,  Late  Low, 
Katherine  Noyes,  Sara  Shay 

Associate  Editor  Tom  Wailgum 

Senior  Writers  Mindy  Blodgett,  Daintry  Duffy, 
Meg  Mitchell,  Susannah  Patton,  Lee  Pender, 

Elana  Varon 

Staff  Writers  Stewart  Deck,  Meridith  Levinson, 
Sarah  D.  Scalet 

Asst.  Managing  Editor,  Production  Steve  King 

Copy  Editors  Kelli  Botta  (Associate),  Kathleen  S. 
Carr,  Emily  S.  Henderson 

Senior  Researcher  Carol  Zarrow 

Editorial  Assistants  Lynne  Z.  Rigolini,  Chloe  Taylor 

Contributors  Robert  Axelrod,  Heather  Baukney, 
Cheryl  Bentsen,  Barbara  E.  Bund,  Michael  D. 
Cohen,  Tom  Davenport,  John  Edwards,  Simson  L. 
Garfinkel,  Fred  Hapgood,  Heather  Harreld,  Tom 
Murphy,  Polly  Schneider,  Beth  Stackpole, 
Constantine  von  Hoffman,  Patricia  M.  Wallington 


How  to  Reach  Us 

E-mail  letters@cio.com 
Phone  508  872-0080 
Fax  508  879-7784 

Address  CIO  Communications  Inc., 

492  Old  Connecticut  Path,  P.O.  Box  9208, 
Framingham,  MA  01701-9208 

Website  www.cio.com 

Subscriber  Services  800  788-4605 
Fax  508  879-7899 
E-mail  denisep@cio.com 

Reprints  Reprints  are  available  by  calling 
RMS  at  717  399-1900,  Ext.  131,  or  via  e-mail 
at  jeffm@rmsreprints.com. 


Editorial  Operations  Manager  Lisa  Jayne  Kerber 
Editorial  Admin.  Coordinator  Karen  J.  Zirpola 
Editorial  Intern  Karen  Witham  Lynch 

DESIGN 

Executive  Director,  Art  and  Design  Mary  Lester 

Art  Director  Lisa  Munroe 

Associate  Art  Directors  Hana  Barker,  Terri  Haas, 
Steve  Traynor 

Graphic  Designers  Susan  W.  Gilday, 

Andrea  Healy,  Robin  B.  Macleod,  Terri  Mitchell, 
Jessica  L.  Sepe,  Maria  Cristina  Villa 

Associate  Graphic  Designers  Kaajal  S.  Asher, 
Chandra  Tallman 

Contributing  Designers  Owen  Edwards,  Leslie 
Anne  Feagley 

WEBSITE 

Senior  VP/General  Manager,  Online  Tim  Horgan 

Web  Editorial  Director  Art  Jahnke 

Senior  Web  Editor  Martha  Heller 

Web  Writer  Emelie  Rutherford 

Web  Operations  Manager  Dagmar  Eiben 

Web  Developer  Ellen  Morey 

Web  Research  Editor  Kathleen  Kotwica 

Web  Producer  Holly  Cuny 

Vendor  Program  Manager  Andy  Burrell 

Assoc.  Web  Developer  Shannon  Macdonald 

Web  Engineer  Kelly  Kimball 

CIRCULATION 

Senior  VP/Circulation  Carol  A.  Spach 
Circulation  Manager  Susan  Woodworth 
Subscription  Svcs.  Manager  Denise  Perreault 
Subscription  Svcs.  Supervisor  Tina  Pescara 
Circulation  Assistant  Lisa  Desmarais 

PRODUCTION 

Director  of  Production  Resa  Altsher 
Production  Associate  Lee  Tuttle 
Ad  Prod.  Coordinator  Marybeth  Travers 

EXECUTIVE  PROGRAMS 

Executive  VP  Lynda  Rosenthal 

VP/Event  Development  &  Planning  Robin  L.  Azar 
Director,  Marketing  Services  Shellie  Rapson  James 
Manager,  Program  Operations  Brian  Fuce 
Manager,  Ancillary  Products  Bill  Kerber 

Manager,  Procurement/Tech.  Planning 

Cynthia  Laird 

Managers,  Program  Development  Sherry  Keyles, 
Thomas  M.  Pitkin,  Michele  Zarella 

Manager,  Client  Services  Jeremy  E.  Draper 


Administrator,  Program  Planning  &  Finance 

Sandra  J.  Hughey 

Program  Application  Specialist  Heather  Beauton 
Program  Marketing  Specialist  Karen  Peabody 

Assoc.  Program  Marketing  Specialist 

Deanna  Burke 

Operations  Coordinator  Michael  Barbato 

Fulfillment  Services  Coordinators  Christine  Cyr, 
Leah  Silver 

Manager,  Event  Planning  Amy  Sanderson 
Event  Planning  Specialist  Rachel  Sherman 

MARKETING 

Executive  VP/Marketing  Cathy  O'Leary  Hayes 
VP/News  and  Information  Susan  Watson 
Media  Relations  Manager  Karen  Fogerty 
News  and  Information  Specialist  Julie  Hanson 
Research  Director  Bridget  Cammarata 

Senior  Marketing  Research  Analyst 

Carolyn  Johnson 

Marketing  Research  Analyst  Denise  Kane 
Marketing  Comm.  Director  Marcy  L.  Dill 
Marketing  Comm.  Manager  Nicole  Glinski 

Sr.  MarCom  Development  Specialist 

Kari  Noah 

Marketing  Specialist  Dot  Caspersen 

ADMINISTRATION 

Executive  VP/Operations  Walter  Manninen 
Assistant  to  the  Publisher  Diane  Martin 
Financial  Manager  Margarita  Chiango 
Billing  Administrator  Joyce  Gillis 
Facilities  Specialist  John  Kelley 
Office  Services  Assistant  Mary  E.  Wooldridge 

INFORMATION  SYSTEMS 

VP/CIO  David  Woodall 

Manager,  Network  Services  James  C.  Burgoyne 
User  Services  Manager  Ron  Bettencourt 
User  Services  Specialist  Michael  Fahlsing 
System  Administrator  Robert  Reagan 

m\DG 

INTERNATIONAL  DATA  GROUP 

President  &  CEO  Kelly  Conlin 
Board  Chairman  Patrick  J.  McGovern 

WBPA 

T  INTERNATIONAL® 


2  6  CIO  JUNE  1,  2000 


www.cio.com 


Ever  wish  multi-platform  network  backup  were  this  easy? 


Presenting  VERITAS  NetBackup™,  the  simplest  way 
to  backup  a  complex  network.  It's  designed  to 
work  with  any  combination  of  platforms,  including 
Microsoft®  Windows®  NT,  UNIX  and  NetWare,  as 
well  as  major  databases  and  applications  like 
Microsoft®  SQL  Server,  Oracle,  Informix,  Sybase, 
Lotus  Notes,  PeopleSoft,  and  SAP  R/3. 

NetBackup  also  gives  you  centralized  control,  and 
with  Global  Data  Manager  (GDM)  you  can  centrally 


manage  backup  and  recovery  operations  any¬ 
where  on  the  planet.  With  surprising  terabyte- 
per-hour  backup  speeds,  and  highly  parallel,  mul¬ 
tiplexed  backup  and  recovery  you'll  get  the  per¬ 
formance  you  need  now. and  in  the  future. 

So  call  1-800-729-7894,  ext.  83512.  or  surf  the 
web  at  www.veritas.com  today.  Because  it's  hard 
to  imagine  an  easier  way  to  backup  a  complex 
network. 


BUSINESS  WITHOUT  INTERRUPTION: 


VERITAS 


WHAT  IF  TURNING  ON  SOFTWARE 
WERE  JUST  AS  EASY? 


That  would  require  an  Application  Service  Provider  like  FutureLink1."  One  with 
an  approach  to  delivering  applications  based  on  a  utility  company  model.  As 
The  Application  Utility  Company  ,"  we  lead  the  industry  in  providing  the  software 
you  need,  anywhere  you  need  it.  On  demand.  Like  getting  water  from  a  faucet. 

With  FutureLink,  your  IT  department  will  be  freed  from  the  time-consuming 
tasks  of  break/fix  and  system  configuration,  just  to  name  a  few.  Why?  Because 
we  take  care  of  delivering,  updating  and  deleting  applications  across  the  entire 
network.  Your  users  enjoy  a  more  productive  computing  experience.  And  you  save 
money.  In  some  cases  as  much  as  60%  on  IT  support  and  hardware  costs  alone. 

With  15  years  of  global  experience  providing  IT  solutions  on  premises  or 
from  one  of  our  world-class  data  centers,  we’re  ready  to  offer  you  the  level 
of  dependability,  flexibility  and  cost  efficiency  your  business  COMPAQ. 
demands.  That  means  24x7  customer  service,  scalable  Compaq  ProLiant® 
servers,  and  software  that  runs  the  gamut  from  Microsoft®  Windows®  and 
Microsoft®  Office  2000  to  other  business  critical  applications.  MiCiOSOft 
It’s  an  idea  that  sounds  too  good  to  be  true.  The  notion  of  water  from  a 
faucet  once  elicited  the  same  response.  For  a  FREE  analysis  of  how  you  might 
be  able  to  save  up  to  60%  on  your  IT  costs  and  turn  on  your  software,  call 
1.877.216.6001  or  visit  us  at  www.FutureLink.net/utility.  And  soon  you’ll  be  able 
to  take  us  for  granted.  Just  like  all  those  other  utilities  you  couldn’t  live  without. 

Futurelink. 

The  Application  Utility  Company  ™ 

www.FutureLink.net/utility 


©  2000  FutureLink.  All  rights  reserved.  FutureLink  and  The  Application  Utility  Company  are  trademarks  of  FutureLink. 
All  other  trademarks  and  registered  trademarks  are  property  of  their  respective  owners. 


HIGH-T  ECH  MATCHMAKING 


The  Data  Game 


IT’S  AN  OLD  STORY,  sort  of.  Boy  meets  girl.  Boy  realizes  he  and  girl  are 
completely  incompatible.  Boy  has  to  find  new  girl. 

“People  waste  a  lot  of  time  with  people  with  whom  they  have  nothing  in  com¬ 
mon,”  says  Ed  White,  an  entrepreneur  who  imagines  instead  an  uber-efficient 
dating  world  where  potential  couples  use  his  infrared  smart  cards  to  determine 
their  compatibility — without  the  small  talk.  After  all,  if  that  hottie  at  the  bar 
doesn’t  appreciate  museums,  cigarettes  and  punctuality, 
why  bother?  “You  look  at  this  very  attractive  guy, 
you  like  what  you  see,”  White  says,  “but  if  the 
score  is  lousy,  you  say,  ‘Next!’” 

Ratings  are  based  on  each 
individual’s  answers  to  a 
quiz  from  a  marriage 
compatibility 
course.  The  96 
questions — in  cate¬ 
gories  such  as 
habits,  beliefs  and 
sex — are  orga¬ 
nized  into  pairs, 
with  the  first  ques¬ 
tion  asking  for  an 
opinion  and  the  sec¬ 
ond  determining  that 
opinion’s  importance. 
The  more  answers  two 
people  have  in  com¬ 
mon,  and  the  more 
weighty  those  answers,  the 
higher  their  compatibility 
score.  The  average  score 
Continued  on  Page  32 


GOLF  ADVICE 

Keeping  the  Faux 
Pas  Below  Par 

WONDERING  WHY  nobody  called 
you  back  after  that  recent  “get-to- 
know-you”  golf  outing?  Maybe  it  was 
something  you  said  or  did— or  didn’t 
say  or  do. 

Now  that  golf  courses  have  become 
a  prime  setting  for  cutting  business 
and  career  deals, 
more  CIOs  are  paying 
attention  to  their 
fairway  etiquette— or 
lack  thereof.  For  the 
manners-challenged, 

Mr.  Golf  Etiquette 
( www.mrgolf.com ) 
has  the  answers. 

The  website,  which 
averages  40,000  to 
50,000  visitors  a 
month,  was  founded 
by  Jim  Corbett,  vice  president  of 
business  development  for  VersusLaw,  a 
law  research  company  located  in 
Redmond.  Wash.  Corbett  has  discussed 
more  than  a  few  business  matters  on 
the  nonhyperlinks,  but  worries  that 
many  duffers  are  blowing  potential 
opportunities.  “Not  everyone  can  be  a 
great  golfer  in  that  they  will  hit  a  score 

Continued  on  Page  32 


‘  WHY  ARE  I.S.  ORGANIZATIONS  BEING  FORCED  TO  HIRE  13-YEAR-OLD 
PROGRAMMERS?  BECAUSE  ALL  OF  THE  GOOD  12-YEAR-OLDS  ARE  TAKEN!” 

-Frank  Gens,  senior  vice  president  of  internet  research  for  IDC,  speaking  at  IDC’s  recent  Directions  conference  in  Boston 


30  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  ERIC  RANK/PHOTONICA;  ILLUSTRATION  BY  GEOFF  SMITH 


Treat  your 
best  e-customers 


like  favorites  and  they’ll 
do  the  same  for  you. 


They  come.  See. 
Maybe  even  buy. 
Then  they  leave. 


And  that’s  when  your  selling  job, 
not  to  mention  your  success  in 
e-commerce,  really  begins. 


The  SAS®  Solution  lets  you  combine  the  Web  data  a  customer  left  you 
seconds  ago  with  the  purchasing,  behavior,  and  demographic  data 
you’ve  been  keeping  all  along.  And  that  makes  it  easy  to: 

Get  to  know  your  e-customers.-delight  them  by  proving  you 
understand  them... personalize  your  interactions.. .and  predict  their 
changing  needs. 

Build  strategies  to  retain  customers...cross-sell  to  them. ..and 
make  the  most  effective  use  of  all  your  marketing  channels. 

Improve  your  Web  site  by  analyzing  who  clicked  on  what  and 
why.. .and  which  pages  customers  come  back  to  most. 

For  a  free  guide,  Taking  the  Guesswork  Out  of  Your  E-Business 
Strategy,  come  to  www.sas.com/favorites  or  give  us  a  call  at 
919.677.8200. 


The  Business  of  Better  Decision  Making 


m 

SAS  Institute 


www.sas.com/favorites  E-mail:  cio@sas.com  919.677.8200 


In  Canada  phone  1.800. SAS. INST  (1.877.727.4678).  SAS  and  all  other  SAS  Institute  Inc.  product  or  service  names  are  registered  trademarks  or  trademarks  of  SAS  Institute  Inc.  in  the  USA  and  other  countnes 
®  indicates  USA  registration.  Other  brand  and  product  names  are  trademarks  of  their  respective  companies.  Copyright  ©  2000  by  SAS  Institute  Inc.  30336_0200 


trendlines 


The  Data  Game 

Continued  from  Page  30 


is  75 — just  like  in  college — and  it’s  up  to  individuals  to  decide  who  makes  the 
grade. 

Those  who  invest  in  the  $29.99  MatchUp  system,  offered  by  Interactive 
Digital  Corp.  (www.matchupsingles.com),  can  take  the  test  on  their  PCs,  down¬ 
load  the  results  to  the  one-ounce,  credit-card-size  smart  card  and  then  point 

their  card  at  someone  else’s.  When  they 
are  within  about  a  foot  of  each  other, 
the  infrared  cards  can  exchange  data 
and  then  display  the  compatibility 
rating  on  the  screens  of  both  cards. 

“My  dream  is  very  simple,”  says 
White,  himself  happily  married. 

“I’d  like  every  single  person  in  the 
world  to  have  one  of  these.” 

Of  course,  if  things  go  well,  every 
couple  in  the  world  may  have  a  pair  of 
MatchUp  cards  taking  up  space  in  the  closet. 

-Sarah  D.  Scalet 


Stay  Below  Par 

Continued  from  Page  30 

below  par.  But  everyone  can  be  a  great 
golfer  in  how  they  act  on  the  course 
toward  their  fellow  golfers,  toward  the 
course  and  toward  the  game  itself,” 
says  Corbett. 

There  is  no  charge  to  visit  Mr.  Golf 
Etiquette  or  to  submit  questions.  Here 
are  a  few  tips  from  the  site: 

■  Be  invisible  (including  your  shadow) 
when  someone  is  hitting. 

■  If  the  caddie  does  a  good  job,  you 
should  reward  him  with  a  decent  tip. 

■  Walk,  don't  run. 

■  If  you  are  driving  a  motorized  cart, 
proceed  at  a  moderate  speed  and  keep 
your  eyes  open  for  other  golfers. 

-John  Edwards 


Maynard 


BY  DARRIN  BELL  AND  THERON  HEIR 


32  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  GEOFF  SMITH 


DOES  YOURS? 


These  companies  have  two  things  in  common:  They  all  depend  upon 
a  reliable  24/7  Internet  presence,  and  they  all  depend  on  siteROCK. 

SiteROCK  is  the  leading  provider  of  remote  e-commerce  site  management 
services.  Our  Reliability  Operation  Centers  are  staffed  by  skilled  IT 
professionals  around  the  clock  and  around  the  world.  These  ROCs  monitor 
and  optimize  the  availability  and  performance  of  your  e-business  systems, 
third-party  dependent  applications,  and  network  providers. 

SiteROCK  delivers  objective  and  actionable  metrics  that  give  you  what 
you  need  most  —  reliability,  visibility,  control,  and  peace  of  mind  —  at  a 
fraction  of  the  cost  of  in-house  solutions. 

Call  us  today  at  1.877. 506. ROCK  or  visit  www.siterock.com 

n  siteROCK 


©  2000  siteROCK  Corporation.  All  rights  reserved.  SiteROCK  and  the  siteROCK  logo  are  service  marks  of 
siteROCK  Corporation.  Other  trademarks  featured  are  the  properties  of  their  respective  owners 


trendlines 


Compiled  by 
Derek  Slater 


Enterprise  Application  Projects 

ENTERPRISE  APPS  ARE  THE  RAGE.  But  truly  successful  implementa¬ 
tions  of  enterprise  resource  planning  (ERP),  supply  chain  management  (SCM), 
customer  relationship  management  (CRM)  and  e-commerce  systems  are  hard  to 
come  by.  A  Boston  Consulting  Group  (BCG)  survey  found  that  only  a  third  of 
project  outcomes  could  be  called  “positive”  or  “strong  positive.”  The  survey 
determined  that  the  odds  of  success  rise  as  project  planners  perform  a  more 
thorough  analysis  of  corporate  processes  and  project  options.  Not  too 
shocking — unless  you  consider  the  number  of  companies  that  don’t  do  it. 


A  thorough  analysis  of  capabilities  improved  outcomes. 


Minimal  analysis  Process  analysis  Process  analysis  Process  analysis 
of  capabilities  and  benchmarking  benchmarking  and 

customer  interviews 


ANALYSIS  ACTIONS_ 1 


Many  large  initiatives  were  undertaken  without  thorough  analysis. 


PERCENT  OF  INITIATIVES  WITH 
THOROUGH  ANALYSIS  OF  CAPABILITIES 


100 
80 
60 
40 
20 
_  0 


PERCENT  OF  INITIATIVES  WITH 
THOROUGH  ANALYSIS  OF  OPTIONS. 


100 
80 
60 
40 
20 
L  0 


Less  than  $3  million  to  $30  million 

$3  million  $29.9  million  or  more 

I  SIZE  OF  PROJECT _ I 


Less  than 
$3  million 


$3  million  to 
$29.9  million 

SIZE  OF  PRQJECL 


$30  million 
or  more 


Best  Practices  for  IT 

1.  Carefully  analyze  the  problems  and 
potential  solutions.  Sometimes  a  software 
implementation  is  not  the  only  answer,  or 
even  the  correct  answer,  for  improving 
corporate  performance,  according  to  the 
report.  In  many  cases,  simple  upgrades  to 
existing  software  are  more  effective  than 
new  systems  implementations. 

One  participant  company  was  under 
the  gun  to  increase  inventory  turns, 
according  to  Hal  Sirkin,  a  BCG  senior 
vice  president  based  in  Chicago.  Rather 
than  buy  a  packaged  SCM  solution, 
however,  the  company  found  after  careful 
analysis  that  it  could  achieve  the  goal  by 
reworking  a  few  critical  work  processes. 

Pre-project  analysis  should  include 
competitor  and  best  practice  benchmarks. 

2.  Scrutinize  vendors  and  costs.  A  third  of 

the  respondents  to  the  BCG  survey  said 
they  believed  their  vendor  encouraged 
unnecessary  spending.  One  in  five  respon¬ 
dents  who  had  implemented  ERP  or  SCM 
solutions  said  they  could  have  achieved 
the  same  business  value  for  much  less  cost. 

3.  Divide  projects  into  manageable  pieces. 

According  to  BCG’s  study,  the  average  size 
of  projects  with  a  strong  positive  outcome 
was  $10  million,  while  the  average  for 
negative  outcomes  was  $90  million.  Said 
one  survey  respondent,  “Divide  and 
conquer....  Do  it  piecemeal  or  none  of  it 
will  be  done  right.” 

4.  Know  when  to  stop.  Establishing  clear 
metrics  is  one  key  to  success.  At  the  end 
of  each  step,  “IS  personnel  have  to  work 
with  business  managers  to  figure  out 
whether  the  next  phase  will  add  sufficient 
value,”  according  to  the  report.  Twenty- 
three  percent  of  respondents  identified 
“lack  of  a  well-defined  endpoint”as  a 
contributor  to  overspending. 


SOURCE:  A  BOSTON  CONSULTING  GROUP  SURVEY  OF  MORE  THAN  100  EXECUTIVES.  FOR  MORE  INFORMATION,  VISIT  WWW.BCG.COM. 

Suggest  future  topics  to  numbers@cio.com. 


34  CIO  JUNE  1,  2000  •  www.cio.com 


. 


p 


1®S 


■ ;  ■'  ■ ..  - 


K 


And  it  can  blow  a  nasty  hole  in  the  side  of  your  company.  The  most  innocent-looking  e-mail 
can  be  a  silent  letter  bomb. 

E-mail  can  circulate  offensive  content  and  get  you  sued.  Or  deliver  your  trade  secrets  to  your 
competitors.  It  can  cripple  your  network  with  spam,  huge  files  and  viruses.  And  sink  employee 
productivity  to  a  new  low. 

Content  Technologies  enables  you  to  work  in  the  e-world  with  total 
content  security.  Find  out  how  to  defuse  dangerous  e-mail  and 
Internet  content  -  before  it  sends  you  into  damage  control. 


Get  a  free  evaluation  copy  of  our  MIMEsweeper  software 
along  with  our  "Guide  to  Content  Security"  CD. 

www.contenttechnologies.com/ads  (888)  888-6883 


ftcontent 

technologies 


MAXIMUM  SECURITY 
FOR  THE  E  WORLD 


©  Content  Technologies  2000 


where  do  millions  of  investors  go  to  follow  the  nasdaq  stock  market®?  not 
to  wall  street,  but  to  nasdaq.com.  to  build  their  web  site,  nasdaq  needed 
high-capacity  servers  that  stay  up  and  running  24/7.  servers  that  can 
handle  up  to  40  million  hits  a  day  and  rising,  the  stock  market  for  the  digital 
world  chose  inteP-based  servers  for  their  e-business,  companies  around  the 
world  have  considered  their  platform  options  and  have  made  the  same 
decision.  inteP  architecture  is  the  ideal  technology  for  running  an  e-business, 
because  in  the  surge  economy,  if  your  business  isn’t  ready  for  anything,  it 
isn’t  ready.  (  servers  for  the  surge  economy  -» intel.com/go/ebiz  ) 


The  Nasdaq  Stock  Market  is  a  registered  trademark  of  The  Nasdaq  Stock  Market,  Inc.  Intel  is  a  registered  trademark  of  Intel  Corporation.  ©  2000  Intel  Corporation. 


•••••• 

•••••• 

Ml**'; 

•••••• 

•••••• 


trendlines 


EXPERTS  ONLINE 

Who  Ya  Gonna  Call? 

YOU’RE  IN  THE  MIDDLE  of  cooking  a  creme  brulee  for  the 
first  time,  and  it’s  just  not  coming  out  right.  No  problem:  Log  on  to 
Keen.com  and  get  immediate  advice  from  a  baking  aficionado  who 
can  speak  with  you  live  before  your  guests  arrive. 

Visitors  to  www.keen.com  can  search  under  a  wealth  of  cate¬ 
gories — home,  health  and  fitness,  computers,  hobbies,  personal 
advice,  parenting  and  so  on — to  see  if  an  expert  is  available  to  talk. 
For  a  fee  set  by  the  expert  (an  average  of  80  cents  per  minute,  but 
ranging  up  to  $10  per  minute  or  higher),  you  can  click  on  an  icon 
and  Keen.com  first  calls  you,  and  then  conferences  in  the  creme 
brulee  chef.  To  protect  privacy,  Keen.com  does  not  release  phone 
numbers,  nor  does  it  sit  in  on  the  call  after  connecting  the  parties. 


The  site  also  allows  the  experts  (both  professionals  and  amateurs 
looking  to  make  a  quick  buck)  to  prerecord  advice  or  send  informa¬ 
tion  by  e-mail — for  a  fee.  But  the  live  calls  are  by  far  the  most  popu¬ 
lar,  says  Karl  Jacob,  CEO  for  the  San  Francisco-based  company,  who 
thought  up  the  idea  while  working  for  venture  capital  company 
Benchmark  Capital.  The  site  has  users  from  Israel  and  Europe,  and  it 
offers  a  translation  service  that  supports  10  foreign  languages,  Jacob 
says.  At  any  given  time,  there  are  some  15,000  experts  available  to 
take  your  call,  and  one  expert  made  $1,500  in  February.  This  is  good 
news  for  Keen.com,  since  it  takes  a  30  percent  cut  of  every  call. 

Drawbacks:  You  can’t  be  sure  of  the  expert’s  qualifications  unless 
the  self-proclaimed  lawyer  or  doctor  has  sent  her  credentials  to 
Keen.com  (not  required);  those  are  then  verified  by  a  third  party 
called  Backgrounds  Online.  And  the  searching  is  a  little  clunky:  The 
phrases  “negotiating  job  benefits”  and  “buying  a  dog,”  for  example, 
came  up  with  nothing.  Entering  “Indian  cuisine”  brought  up  one  indi¬ 
vidual  named  Rose  whose  bio  reads:  “I  love  Indian  food  but  don’t 
know  how  to  make  it.”  My  thoughts,  exactly!  -Polly  Schneider 


HOT  TOPIC 


The 
Firing 
Line 

By  Mindy  Blodgett 

It  may  be  true  that  the  economy  is  booming  and 
qualified  labor  is  in  short  supply,  but  that  doesn’t 
mean  managers  aren’t  still  occasionally  faced  with 
the  grim  task  of  firing  employees.  It’s  never  easy, 
but  now  there's  help:  The  Employment  Roundtable, 
a  New  York  City-based  nonprofit  consortium  of 
business,  government  and  think  tank  leaders, 
recently  released  "Letting  People  Go  with  Dignity,”  a 
report  on  handling  employment  terminations. 

Today’s  hot  labor  market  makes  it  more  impera¬ 
tive  than  ever  that  terminations  be  handled  in  a 
sensitive  manner,  says  Richard  Bayer,  cochair  of  the 
Employment  Roundtable  and  COO  of  The  Five 
O’clock  Club,  a  New  York  City  career  counseling 
organization  that  started  the  roundtable  in 
December  1998.  "You  need  to  be  able  to  recruit  and 
retain  good  people,  and  your  ability  to  do  that  is 
facilitated  by  your  reputation  in  the  marketplace,” 
he  says.  When  disgruntled  ex-employees  complain 
about  unfair  treatment,  that  reputation  can  suffer. 
"You  also  have  to  be  concerned  with  the  morale  of 
the  remaining  workforce,"  Bayer  adds. 

The  roundtable  offers  a  number  of  tips  for  the 
manager  doing  the  firing,  including  the  following: 

■  Explain  to  the  employee  what  went  wrong.  That 
information  can  make  it  easier  for  him  or  her  to 
move  on  and  leave  the  job  behind. 

■  Make  sure  to  explain  how  the  employee’s  depar¬ 
ture  will  be  publicized. 

■  Let  the  employee  return  to  his  or  her  desk  and 
share  reactions  with  friends  on  staff.  This  allows 
him  or  her  to  gather  some  dignity  and  normalcy 
and  to  feel  empowered,  not  railroaded. 

For  more  information,  visit  www.5occ.com/ 
roundtable. 


38  CIO  JUNE  1,  2000  •  www.cio.com 


LLUSTRATION  BY  JENNIFER  HERBERT;  PHOTO  BY  TONY  STONE  IMAGES 


Who  says 
you  can't  teach 
an  old  dog 
new  tricks? 

Tracking  down  legacy  information  is 
what  Attachmate®  e-Vantage™  was 

bred  to  do.  It's  the  only  web-based 
host  access  solution  that  supports 
IBM?  Java™  and  Microsoft®  standards 
in  any  combination  you  prefer.  That's 
how  your  employees,  partners  and 
customers  can  get  exactly  the  infor¬ 
mation  they  need  when  they  need  it. 
Unleash  the  power  of  your  legacy 
applications.  Make  them  available  to 
browsers  everywhere.  For  the  free 
booklet,  Web-to-Host  Success  Profiles, 
just  give  us  a  call  at  1-800-933-6793 
(ext  4336).  Or  point  your  browser  to 
www.attachmate.com/ad/cio.asp 


= Attachmate 

The  Advantage  of  Information™ 


©  2000  Attachmate  Corporation.  All  Rights  Reserved.  Attachmate  is  a  registered  trademark  and  e-Vantage  and  The  Advantage  of  Information  are  trademarks 
of  Attachmate  Corporation  IBM  is  a  registered  trademark  of  International  Business  Machines  Corporation  Java  is  a  trademark  or  registered  trademark  of  Sun 
Microsystems,  Inc.  in  the  United  States  and  other  countries.  Microsoft  is  a  registered  trademark  of  Microsoft  Corporation.  00-0026B  0200 


trendlines 


An  Electronic  Gumshoe 

IN  THIS  WORLD  of  virtual  com¬ 
munications  and  interaction,  how  do 
you  ever  really  know  who  you’re  talking 
to?  You  don’t,  and  therein  lies  a  world 
of  opportunity  for  con  artists,  scam- 
sters,  grifters  and  deadbeats.  Indeed, 
identity  fraud  is  the  crime  of  the  new 
millennium,  says  Ross  Silverman, 
chairman  of  the  antifraud  counseling 
litigation  department  of  Katten  Muchin 
Zavis  in  Chicago. 

One  tool  that  can  help  uncover  the 
crooks  is  InfoGlide  Corp.’s  Fraud 
Investigator  software,  which  peers 
behind  seemingly  innocuous  data  to 
detect  suspicious  patterns  that  may  indi¬ 
cate  a  person  is  posing  under  several  dif¬ 


ferent  names  or  making  up  Social 
Security  numbers,  says  Jay  Val¬ 
entine,  CEO  of  the  Austin,  Texas- 
based  company.  “It  identifies 
instances  of  fraud  that  escape  tra¬ 
ditional  exact-match  searches.” 

The  XML  Similarity  Engine  that 
powers  Fraud  Investigator  discov¬ 
ers  links  between  different  data 
files  and  databases  by  making  sure 
that  slight  variations  in  names, 
addresses,  phone  numbers  or  other 
identifying  data  won’t  be  excluded  from 
a  search’s  end  results.  The  engine  then 
converts  the  data  into  a  hierarchical  for¬ 
mat  and  compares  it  to  likely  matches, 
ranking  it  with  user-defined  attributes. 


Fraud  Investigator  costs  between 
$5,000  and  $35,000  per  month,  de¬ 
pending  on  exact  capabilities  and  usage. 
For  more  information,  visit  www. 
infoglide.com.  -John  Edwards 


In-House  or 

One:  Most  everybody  knows  that  supply 
chains  are  ripe  for  transformation  and 
are  a  critical  strategic  area  for  the  inter¬ 
net  economy. 

Two:  Many  companies  nevertheless  don't 
know  what  their  supply  chain  manage¬ 
ment  strategy  is,  or  even  how  well  their 
operations  perform. 

Those  are  the  common  conclusions  of  two  recent  surveys  of 
senior  executives  regarding  supply  chain  management.  One 
survey  of  80  Fortune  500  executives— “Moving  the  Supply 
Chain  into  the  Digital  Age:  Integrating  Demand  and  Supply”— 
comes  from  London’s  Economist  Intelligence  Unit  (EIU),  which 
is  a  member  of  global  communications  company  Economist 
Group,  and  Meritus  Consulting  in  New  York  City.  The  second 
poll— "The  Millennium  Manufacturing  Supply  Chain  Survey"— is 
from  Reston,  Va. -based  consultancy  Compass  America,  with  a 
response  base  of  258  senior  supply  chain  executives  in  North 
America,  Europe  and  Australia. 

In  the  EIU  survey,  82  percent  of  the  respondents  said  they 
believe  the  internet  will  have  a  major  impact— or  even  com- 


OutSOU  TC0Cl? By  Derek  Slater 

pletely  transform— supply  chain  performance  over  the  next 
three  years.  Yet  nearly  a  third  of  them  were  unable  to  estimate 
the  supply  chain  performance  of  their  own  organizations. 
Similarly,  70  percent  of  the  Compass  respondents  indicated 
that  a  supply  chain  strategy  is  necessary  for  achieving  compet¬ 
itive  advantage.  However,  nearly  60  percent  said  their  own 
strategy  is  either  nonexistent  or  lacking  detail,  and  50  percent 
described  “limited  formal  means  of  measuring  supply  chain 
performance."  The  upshot,  according  to  Andrew  Johnson,  head 
of  Compass’s  practice  for  manufacturing,  is  that  executives 
have  trouble  understanding  what  effect  their  strategy  decisions 
truly  have  on  supply  chain  performance. 

What’s  even  more  interesting,  of  course,  is  how  companies 
plan  to  solve  that  problem.  Compass  says  many  respondents 
are  looking  to  IT  for  the  solution;  60  percent  anticipate  rising 
technology  expenditures  to  address  SCM.  That  number 
matches  up  interestingly  with  the  EIU  finding  that  40  percent 
of  its  respondents  plan  to  outsource  their  distribution  and 
transportation  functions  within  the  next  three  years. 

For  the  EIU  survey,  visit  www.eiu.com.  More  information  on 
the  Compass  study  can  be  found  at  www.compassamerica.com. 


40  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  RIGHT  BY  ROB  D.  CASEY/STONE  IMAGES;  PHOTO  LEFT  BY  PHOTONICA 


High  Performance 


Mission-Critical 


Internet  Site  Operations 


If  Your  Site 

Isn’t  Running  Like  Clockwork, 
Consider  This 
Your  Wakeup  Call. 

Internet  site  traffic  is  increasing  daily.  Your  company  is  creating  the  buzz  you  always  dreamed  of  -  about  the  only  thing  on  your  mind  is 
reaching  your  next  million  visitors.  Then  it  hits  you.  Can  your  Internet  site  scale?  Are  you  vulnerable  to  a  security  problem  or  dependent  on  a  single  network  that 
could  experience  an  outage?  Real  reasons  to  lose  sleep  at  night.  Enter  SiteSmith,  the  people  with  the  experience  and  tools  to  put  your  worst  Internet  nightmare 
to  rest.  SiteSmith  manages  Internet  site  operations  for  some  of  the  hottest  new  Internet  start-ups  as  well  as  the  best-known  industry  leaders.  SiteSmith  is  your 
best  assurance  that  your  site  will  continue  to  run  like  clockwork.  Visit  our  website  at  www.sitesmith.com  or  call  toll  free  1-877-748-3002.  The  sooner  you  do,  the 
sooner  you  can  stop  worrying  and  start  catching  up  on  your  sleep. 


SITES  DON'T  WORK  WITHOUT  US. 


We’ve  been  building  security  longer  than  you  think 


»v .> 


way  secure  Informix  has  been  building  enterprise-level 
security  as  long  as  there  have  been  web  sites.  Our  encryption  and  decryption  software  is 
built  straight  into  the  database  for  lightning  fast  security  operations,  complete  stability  and 
total  extensibility.  That  means  Informix  Internet  Foundation. 2000  is  the  only  secure  database 
you  will  ever  need.  Because  when  it  comes  to  security,  experience  matters. 


1 


security. 


strength,  stability 


lnform/x 

SOFTWAR  E 

way  to  web 


www.informix.com 


r 


trendlines 


RECRUITING 


Move  Over,  Silicon  Valley 


HIGH-TECH  COMPANIES  are  flour¬ 
ishing,  venture  capital  is  flowing  and 
spacious  loft  apartments  are  affordable 
and  plentiful. 

Sound  like  Shangri-la? 

It’s  the  latest  pitch  for  Atlanta,  where 
the  local  chamber  of  commerce  has  hired 
a  full-time  recruiter  specifically  to  attract 
young  technology  workers  with  promises 
of  jobs,  a  low  cost  of  living,  exciting 
night-life  and  sports  events  galore. 
“People  think  of  Atlanta  as  a  small,  sleepy 
Southern  town,”  says  Rosita  Smith,  the 
new  director  of  talent  development  for  the 
Metro  Atlanta  Chamber  of  Commerce. 
“We  want  people  to  know  that  it’s  a 
vibrant  and  diverse  community  and  a  cul¬ 
tural  place.” 

The  Atlanta  area  ranks  10th  in  the 
nation  in  high-tech  jobs,  according  to 
Hans  Gant,  senior  vice  president  of  eco¬ 
nomic  development  for  the  Atlanta  cham¬ 
ber.  But  as  in  other  technology-friendly 
cities,  the  workforce  isn’t  meeting  the  de¬ 
mand.  Under  pressure  from  Atlanta’s 
roughly  10,000  technology  companies — 
led  by  AT&T,  BellSouth  and  Lockheed 


Martin — the  chamber  launched  a  $4  mil¬ 
lion  nationwide  advertising  and  recruiting 
blitz  last  year  to  attract  startups  and  fill 
the  widening  gap  between  technology  jobs 
and  workers.  Just  before  hiring  Smith  in 
February,  the  chamber  launched  a  slick 
new  website  complete  with  job  listings 
and  photos  of  loft  interiors. 

Smith,  the  former  associate  director  of 
career  services  at  the  Georgia  Institute  of 
Technology,  has  been  charged  with 
spreading  the  good  word  about  Atlanta  by 
traveling  to  college  campuses  and  recruit¬ 
ing  fairs  across  the  country.  She  also  plans 
to  bring  local  academics  and  industry 
leaders  together  to  help  find  ways  of  bet¬ 
ter  preparing  students  for  the  job  market. 

It’s  too  early  in  the  five-year  effort  to 
judge  results,  Smith  and  Gant  say.  But 
traffic  on  www.atlantasmartcity.com  rose 
20  percent  in  its  second  month  after 
receiving  200,000  hits  in  February.  And 
other  communities  are  taking  note  of  the 
initiative  and  seeking  advice  from  the 
Atlanta  chamber.  “So  far,  we’ve  been 
pleasantly  surprised,”  Smith  says.  “People 
are  noticing  us”  -Susannah  Patton 


ROLE  M  O  DELS 

Whom  Do 
You  Admire? 

BILL  GATES  may  have  his 
share  of  legal  problems,  but 
he’s  also  got  some  loyal  fans 
in  the  IT  community.  In  a 
recent  survey  by  RHI  Con¬ 
sulting  ( www.rhic.com )  in 
Menlo  Park,  Calif.,  1,400 
CIOs  were  asked  who  in  the 
technology  field  they  admire 
most,  and  Billy  the  Kid 
topped  the  list: 

37%  Bill  Gates 

(chairman  and  chief  software 
architect  for  Microsoft) 

19%  Michael  Dell 

(chairman  and  CEO  for  Dell) 

9%  Steve  Jobs 

(CEO  of  Apple  Computer) 

7%  Linus  Torvalds 

(Linux  inventor) 

5%  William  Hewlett 

(cofounder  of  Hewlett-Packard) 

3%  Scott  McNealy 

(chairman  and  CEO  of  Sun 
Microsystems) 

3%  Larry  Ellison 

(chairman  and  CEO  for  Oracle) 

17%  Other/Don’t  know 

In  this  category,  survey 
respondents  named  Marc 
Andreeson,  cofounder  of 
Netscape;  John  Chambers, 
president  and  CEO  of  Cisco 
Systems;  Eric  Schmidt,  chair¬ 
man  and  CEO  of  Novell  and 
Andy  Grove,  chairman  of  Intel. 


44  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  STAN  KAADY 


Finally,  an  upgrade  for  the 
most  important  part  of  any 
business  network.  Michelle. 


mm 


m  s'  "i 


- 


mm 


mm 


|g  Leading  IT  professionals,  experienced  in  real-world  situations,  are  integral  to  the  successful 
. . .  upgrade  of  any  IT  infrastructure.  The  MCSE  certification  offers  a  means  of  identifying  IT 


'  \¥  ’Pi 

M  I 

i  lag  g  m  1 1 1 


professionals  who  have  the  technical  abilities  needed  to  help  their  organizations  implement 
MicrosoftfeffiljjUBi  leading-edge  business  solutions  based  on  the  most  advanced  Microsoft® 
systemsE^neer - -™  technology.  MCSEs  equipped  with  the  skills  needed  to  implement 
Windows®  2000,  the  business  operating  system  for  the  next  generation  of  PC  computing,  can 
assume  a  leadership  role  in  helping  their  employers  or  clients  stay  competitive.  To  find 
out  how  an  MCSE  can  help  your  company,  visit  www.microsoft.com/mcp/. 


mmfr&ZW; 


■ 


wmmM 


Where  do  you  want  to  go  today?’ 


trendlines 


On  the 
Move 


Compiled 
by  Tom  Field 


Rubin  Retires  from  Elf  Atochem 


WE  CATCH  Bob 

Rubin  on  his  last 
day  of  work.  It’s 
Friday,  March  31, 
and  although  his 
retirement  isn’t  offi¬ 
cial  until  June,  the 
58-year-old  senior 
vice  president  and 
CIO  of  Philadelphia-based  Elf  Ato¬ 
chem  North  America  has  decided  to 
use  his  accumulated  vacation  time  and 
just  enjoy  springtime  in  Pennsylvania. 
“I  want  to  do  things  I  haven’t  had  time 
to  do,”  Rubin  says.  “I  want  to  sit 


Bob  Rubin 


outside,  do  some  gardening,  just  read 
a  book.” 

Not  a  bad  way  to  unwind  from  an  IT 
career  that  spans  nearly  four  decades.  In 
all,  Rubin  has  spent  35  years  in  IT — the 
last  15  of  them  at  global  chemical  com¬ 
pany  Elf,  which  is  a  pretty  remarkable 
ride  for  a  CIO.  In  his  time  at  Elf,  Rubin 
has  been  a  part  of  mergers  and  acquisi¬ 
tions;  he  oversaw  a  swift  and  successful 
SAP  rollout;  and  he  managed  his  IT 
shop  so  well  that  he  developed  a  na¬ 
tional  reputation  as  an  IT  leader.  Rubin 
even  served  as  a  CIO  editorial  advisor. 

Short  term,  Rubin  will  be  replaced  by 


Gerard  Benetau,  a  senior  business  exec¬ 
utive  from  Elf’s  French  parent  company, 
Elf  Aquitaine.  Benetau  will  serve  as 
interim  CIO  for  the  rest  of  this  calendar 
year,  after  which  Rubin’s  lieutenant, 
David  Seifert,  currently  vice  president  of 
strategic  planning,  will  step  up  to  be  the 
permanent  CIO. 

Long  term,  Rubin  hardly  sees  himself 
fading  away  in  retirement.  Once  he’s 
had  a  chance  to  unwind  and  recharge, 
he  expects  to  pursue  some  ventures  he’s 
always  been  interested  in  but  never  had 
time  for — namely,  serving  on  corporate 
boards,  doing  some  senior-level  consult¬ 
ing  as  well  as  writing  and  teaching 
about  IT  management.  “I  think  the 
skills  I’ve  learned  and  the  scars  I’ve 
earned  over  the  years  can  be  useful  to 
people  in  each  of  those  arenas,”  says 
Rubin.  He  also  plans  to  be  active  in  his 
wife  Marilyn’s  home-based  consultancy, 
Valley  Management  Consulting. 

But  before  he  gets  back  down  to  busi¬ 
ness,  Rubin  has  some  plans  for  his  first 
week  without  work.  “We’re  going  to 
sleep  a  little  later  than  normal,  then  go 
out  for  a  very  nice  lunch — I’ve  already 
got  some  restaurants  in  mind,”  Rubin 
says.  “And  then  we’ll  just  do  whatever 
comes  to  mind.” 


Player’s  Guide 


Springs  Industries 


Ray  E.  Greer 

Formerly  vice  president  and  CIO  at  Philips  Electronics  China  Group,  Greer  has  been  appointed  senior  vice 
president  and  CIO  at  Springs  Industries,  a  Fort  Mill,  S.C. -based  home  furnishings  manufacturer. 


Louisville,  Ky„  The  Courier-Journal 


Charles  W.  Johnson  iiiwii»iiiiiiiiniiwiiiii»iin»iii»«iiinimiiiii— 

A  20-year  IT  veteran,  Johnson  has  been  named  the  first-ever  vice  president  of  information  technology  at 
the  Louisville,  Ky.,  The  Courier-Journal  newspaper.  Previously,  Johnson  was  director  of  IS  at  The  Courier  & 
Press  in  Evansville,  Ind. 


Jeff  von  Gillern  . . . fry  ■  IronPlanet  Inc. 

has  been  named  CIO  of  IronPlanet,  a  Palo  Alto,  Calif.-based  online  brokerage  for  used  heavy-construction 
equipment.  Formerly  senior  vice  president  of  processing  services  at  Visa  International,  von  Gillern  is  respon¬ 
sible  for  managing  IronPlanet's  customer  service/inside  sales  center,  IS  and  all  web  operations. 


Paul  B.  Hutchison  III 


FuelSpot.com 


has  been  appointed  COO  and  CIO  at  FuelSpot.com  in  Lowell,  Mass.,  an  e-commerce  portal  for  the  energy 
products  industry.  In  this  role,  Hutchison  will  oversee  operations  and  customer  service  and  will  be  responsi¬ 
ble  for  developing  and  implementing  FuelSpot.com's  web  infrastructure,  desktop  applications  and  integra¬ 
tion  with  customers’  back-office  systems. 


46  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  TOP  BY  EUGENE  MOPISK;  PHOTO  BOTTOM  BY  ARTHUR  TRESS 


©2000  PeopleSoft,  Inc.  PeopleSoft  i  the  PeopleSoft  logo  ore  registered  trademarks  of  PeopleSoft  Inc.  All  other  trademarks  ore  owned  by  their  respective  holders. 


Professional  Services  Automation 


Introducing  PeopleSoft  PSA:  100%  Internet  architecture  •  Integrated  people,  projects,  and  prof  its  management 

With  a  PeopleSoft  Professional  Services  Automation  solution  you  can  manage  everything  from  recruitment  to 
contract  administration  to  project  billing.  And  we’ve  even  taken  the  process  a  step  farther.  Usingthe  Internet,  we 
can  help  you  maximize  profitability  by  managing  customer  engagements  and  employee  utilization,  no  matter 
where  your  people  happen  to  be.  That’s  why,  with  over  150  professional  service  customers  to  date,  we’ve  become 
one  of  the  most  trusted  names  in  helping  companies  manage  their  most  profitable  asset  -  people. 


V 


trendlines 


I.T.  EDUCATION 

A  Mold  for  the  Next  Generation 


YOU  KNOW  the 

refrain  by  heart:  We 
need  qualified  IS 
workers  with  busi¬ 
ness  skills,  and  we 
need  them  now.  Well 
cheer  up:  In  a  bid  to 
quiet  rumblings  from  industry  leaders,  a 
group  of  IS  academics  has  published  a 
model  graduate  curriculum  they  believe 
will  help  turn  out  business-proficient  IT 
professionals  at  an  exponential  rate. 

The  new  curriculum  for  the  MS  degree 
in  IS  brings  the  previous  model,  pub¬ 
lished  in  1982,  into  the  internet  age  with 
courses  ranging  from  data  networking  to 
IT  policy  and  strategy.  “When  we  went 


out  to  talk  to  industry,  the  cry  was  rele¬ 
vance,”  says  Paul  Gray,  professor  at 
Claremont  Graduate  University’s  School 
of  Information  Science  in  Claremont, 
Calif.,  and  cochair  of  the  curriculum 
committee,  made  up  of  members  of  the 
Association  for  Computing  Machinery 
(ACM)  and  the  Association  for  Inform¬ 
ation  Systems  (AIS). 

The  curriculum,  published  in  January, 
is  designed  to  tempt  a  diverse  group  of 
students.  “If  you  attract  only  the  normal 
techies,  you  don’t  add  to  the  workforce,” 
says  John  T.  Gorgone,  Rubin  professor 
of  computer  information  systems  at 
Bentley  College  in  Waltham,  Mass.,  and 
cochair  of  the  curriculum  committee. 


Students  new  to  the  field  start  out  with 
a  series  of  IT  and  business  foundation 
courses  such  as  IT  hardware  and  soft¬ 
ware,  and  financial  accounting.  Core 
courses  include  data  management,  pro¬ 
ject  and  change  management,  and  data 
communications  and  networking,  as  well 
as  systems  integration.  To  finish  up,  stu¬ 
dents  take  career  electives  that  can  be  tai¬ 
lored  to  the  regional  needs  of  industry. 

Some  schools  are  already  using  the 
curriculum,  although  officials  don’t 
know  exactly  how  many.  And  more 
could  be  signing  on  soon:  While  50  U.S. 
schools  advertised  a  master’s  in  IS  pro¬ 
gram  three  years  ago,  more  than  100 
now  offer  the  degree.  -Susannah  Patton 


IF  THE  PRESS  releases  are  any  indication,  there  seems  to 
be  a  heady  competition  among  database  vendors  these  days 
to  see  which  can  build  the  biggest,  baddest  database  ever. 

Take  IBM,  which  announced  this  winter  that  in  partnership 
with  EMC  and  Oracle,  it  had  built  the  world’s  largest  single¬ 
system  data  warehouse— 82  terabytes  of  deal-sealing  proof  that 
it  could  protect  British  Telecom  on  the  customer  playground. 

The  system  sounds  pretty  hefty.  After  all,  it  could  hold  enough 
information  to  fill  three-drawer  file  cabinets  lined  up  from  Miami 
to  Seattle. 

But  that's  not  so  tough,  say  the  folks  at  NCR,  who  lay  claim 
to  the  world’s  largest  data  warehouse  in  operation.  Wal-Mart's 
data  warehouse  (for  the  record,  it  uses  parallel  architecture 
rather  than  single-system)  could  hold  a  whopping  101  terabytes, 
enough  to  stuff  those  file  cabinets  from  Miami  to  Juneau, 

Alaska.  And  Wal-Mart  is  just  one  of  166  customers  with  systems 
exceeding  a  terabyte,  a  spokesperson  says.  “NCR  is  the  only 
company  with  more  than  100  data  warehouses  of  1  terabyte  or 
greater  on  a  single  platform." 


Jabs  back  IBM:  “IBM  now  counts  187  customers  with  more 
than  a  terabyte  of  data,  eclipsing  NCR's.” 

Of  course,  as  everyone  knows,  size  isn’t  everything.  The 
volume  of  data  actually  stored  is  more  significant,  says  Richard 
Winter  of  Waltham,  Mass. -based  Winter  Corp.  Toward  that  end, 
Winter  Corp.  will  announce  this  month  new  winners  of  a  contest 
for  the  world’s  largest  database.  Visit  www.wintercorp.com. 

-Sarah  D.  Scalet 


My  Database  Can  Beat 
Up  Your  Database 


48  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  JOHN  RILEY/STONE  IMAGES:  ILLUSTRATION  BY  GEOFF  SMITH 


;j  predict  future  happiness 

-o  *  * 

\  /for  Americans,  especially 

{  ?  <«  ^ 

w^>Hif  this  teleworker  inte 
gration  thing  really  takes  off 


As  foretold,  the  age  of  integrated  voice  and  data  has 
come,  changing  the  lives  of  everyone  in  your  company. 

Alcatel  has  realized  the  full  potential  of  network 
convergence.  Ideas  such 
as  sorted,  prioritized 


Alcatel's  OmniPCX  4400  does  everything  a  PBX 
does,  and  much  more.  With  99.999%  reliability  and 
a  distributed  client/server  architecture,  OmniPCX  4400 

is  designed  to  deliver 
powerful  converged 


e-mail  and  voicemail 
messages,  dial  by  name, 
integrated  keyboards 
and  phones  built  into 
PCs  are  now  reality. 

Provide  your  Web  customers  with  direct  contact  to  a 
service  agent  equipped  with  customized  data.  Let  your  critical 
contacts  reach  you  anytime,  anywhere,  with  a  single  number. 


PROPHECY  FULFILLED: 

OmniPCX  4400  gives  teleworkers  all 
the  capabili  ties  of  a  corporate  PBX 


applications  to  compa¬ 
nies  ranging  all  the 
way  from  50  to  more 
than  50,000  people, 
serving  the  needs  of 
business  for  the  next  decade  and  well  into  the  future. 

Alcatel.  120,000  people.  Internet,  enterprise,  and 
telecom  solutions  worldwide.  www.OmniPCX.com/ads 


T 


©  2000  Alcatel. 


ARCHITECTS  OF  AN  INTERNET  WORLD 


FOR  A  NOT  SO  PRETTY  WORLD. 

THINK  YOUR  E-BUSINESS  IS  SECURE?  THINK  AGAIN. 
FIREWALLS,  INTRUSION  DETECTION,  PKI?  NOT  ENOUGH*. 


PITBULL  PITBULL 


FOUNDATION 


com  Pack 


FIND  OUT  WHY.  READ  THE  NSA  REPORT:  “The  Inevitability  of  Failure:  Flawed  Assumption  of 
Security  in  Modern  Computing  Environments",  U.S.  National  Security  Agency  (NSA)  Report,  1998. 


UNLEASH  THE  BEAST. 

INTRODUCING  A  NEW  BREED  OF  TRUSTED  FOUNDATION  SECURITY  BUILT  TO 
PROTECT  YOUR  E-BUSINESS  FROM  THE  CORE.  PITBULL,  FROM  ARGUS  SYSTEMS 
GROUP,  INC.  THE  NEW  FACE  OF  SECURITY  FOR  A  NEW  ECONOMY. 
WWW.ARGUS-SYSTEMS.COM/PRETTYFACE 


COPYRIGHT  ©2000  ARGUS  SYSTEMS  GROUP.  INC  »>  All  RIGHTS  RESERVED  »>  FOR  ARGUS  TRUSTED  OS  SECURITY  CALI  »> 


Career  Counsel 

Mark  Polansky  Offers  Advice  to  Aspiring  CIOs  and  IT  Managers 


Steppin 

Out 

Q:  I  am  looking  to  re-enter  IT  at  a  director  level.  I  have  10  years’ 
experience  in  information  technology  managing  large-scale 
mainframe  and  client/server  projects.  For  the  past  three  years 
I  have  been  a  director  in  a  corporate  strategy  group  focusing 
on  long-term  strategy.  To  date,  many  of  the  discussions  I’ve 
had  have  ended  with  a  concern  over  my  lack  of  hot  new  skills. 
Am  I  going  to  have  to  take  one  step  back  before  I  can  take  two 
steps  forward? 

A:  Your  first  choice  should,  of  course,  be  a  step  sideways  and 
then  two  steps  forward.  I  have  to  believe  that  there  are  com¬ 
panies  out  there  that  can  use  your  mainframe  and  client/server 
project  experience  today,  while  you  look  for  internal  opportu¬ 
nities  to  add  “the  new  stuff”  to  your  portfolio.  Maybe  it’s  the 
director  title  that  is  throwing  you  off  track. 

I  don’t  think  that  you  will  wind  up  in  the  top  or  No.  2  IT 
seat  after  your  strategy  sidebar,  unless  the  move  is  made  within 
your  current  company.  Then  again,  is  the  lack  of  new  skills 
being  used  as  an  easy  exit  for  interviewers  who  see  some  other 
deal  breaker  and  can’t  or  won’t  say  so?  Get  some  honest  and 


objective  third-party  advice  on  your  interview  presentation 
package. 


FEELING  THE  BURNOUT 

Q:  I’m  the  director  of  IT  at  a  midsize  manufacturing  company. 
Among  other  successful  projects,  I  led  a  major  enterprise 
resource  planning  software  implementation.  The  stress  and 
burnout  has  caught  up  to  me,  and  I  would  now  like  to  move 
into  an  educational  position.  How  can  I  make  the  move  from 
an  information  technology  professional-management  position  to 
an  information  technology  teaching  position  at  either  the  col¬ 
lege  or  high  school  level? 

A:  Before  you  steer  your  career  into  the  world  of  education, 
be  careful.  Make  sure  you  aren’t  overreacting  to  the  stress  and 
strain  of  your  ERP  project.  The  world  of  education  can  be  an 


5  2 


CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  JIM  DEACON 


It  starts  with  a  simple  idea. 


Make  e-commerce  easy.  It  becomes  a  chain  reaction. 
And  incites  a  revolution  that  doesn't  divide. 

It  unifies. 


\ 


© 2000  OrderFusion  Inc. 


The  B2B  sell-side  e-commerce  platform. 
Call  888.653.8096  or  visit  www.orderfusion.com. 


Career  Counsel 


extremely  rewarding  one  despite  its  lower  pay  scale  and  lack 
of  equity  possibilities.  But  it  is  culturally  and  environmentally 
very  different  from  what  you  have  been  accustomed  to. 

If  you  are  indeed  ready,  check  out  the  position  announce¬ 
ments  in  higher  education,  both  in  teaching  and  practicing  IT, 
at  www.educause.edu ,  the  website  of  Educause,  an  interna¬ 
tional  nonprofit  association  whose  mission  is  to  help  shape 
and  enable  transformational  change  in  higher  education 
through  information  resources  and  technologies.  And  check 
out  www.chronicle.com — the  website  of  The  Chronicle  of 
Higher  Education ,  which  lists  some  primary  education  open¬ 
ings  as  well  as  college-level  opportunities.  Also,  give  serious 


consideration  to  the  broader  universe  of  nonprofit  associations, 
organizations  and  foundations.  These  employers  offer  similar 
environmental  factors  and  rewarding  missions  as  does  the  field 
of  education. 

TRANSITION  GAME 

Q:  I  am  a  management  consultant  in  a  Big  Five  firm.  Can  you  tell 
me  what  additional  background  experience  or  skills  companies 
seek  when  they  recruit  new  executives?  And  does  the  school 
at  which  one  receives  an  MBA  make  that  much  difference  as 
long  as  it  is  ranked  within  the  top  20? 

A:  The  transition  from  Big  Five  consulting  to  corporate  infor¬ 
mation  technology  is  an  issue  of  operating  management  expe¬ 
rience.  While  your  time  in  a  Big  Five  firm  has  undoubtedly 
sharpened  your  analytical,  project  management,  communica¬ 
tion  and  interpersonal  skills,  you  have  not  yet  had  a  chance  to 
head  up  and  manage  a  piece  of  a  business-aligned  IT  function, 
with  long-term  political  considerations  and  performance  mea¬ 
surement  criteria. 

This  is,  happily,  a  change  readily  accepted  by  most  but  not 
all  companies  with  the  assumption  that  Big  Five  people  are 
smart  and  savvy  individuals  who  can  make  the  transition  suc¬ 
cessfully.  And  an  MBA  from  any  top  20  university  is  fine,  but 
there  is  a  bit  of  difference  between  the  top  10  and  the  next  10. 
Within  those  ranges,  choose  the  school  that  has  the  best  repu¬ 
tation  for  your  area  of  interest.  For  example,  look  at  Whar¬ 
ton  for  corporate  finance,  check  out  Northwestern  for  mar¬ 
keting  and  Harvard  for  entrepreneurial  management. 


PASSED  OVER 

Q:  I  was  recently  interviewed  for  a  CIO  position  within  my  com¬ 
pany  and  was  considered  one  of  the  top  candidates.  However, 
the  position  was  awarded  to  another  candidate.  I  would  like  to 
pursue  other  CIO  positions  discreetly,  either  through  search 
firms  or  advertised  positions.  My  background  is  primarily  IT 
(15  years),  with  the  last  four  years  focused  on  e-commerce.  I 
have  both  a  bachelor’s  in  computer  science  and  an  MBS  degree. 
What  would  be  the  best  way  to  start  the  search? 

A:  The  first  step,  of  course,  is  to  craft  a  great  resume.  Make  sure 
to  emphasize  your  relevant  experiences  and  accomplishments 
and  get  some  trusted  senior  executives,  both  IT  and 
non-IT,  to  review  it. 

Second,  keep  your  eye  on  the  important  public 
sources  of  position  announcements  and  advertise¬ 
ments — but  remember  that  only  a  fraction  of  CIO 
openings  are  advertised. 

Third,  make  contact  with  a  select  group  of 
search  consultants  who  are  well  known  for  their 
work  recruiting  chief  information  officers.  There 
are  many  directories  of  executive  recruiters,  for  example,  the 
one  available  from  Kennedy  Information  ( www.kennedyinfo 
.com)  is  particularly  helpful  because  it  is  indexed  by  industry 
and  functional  specialty  as  well  as  by  geography.  You  will  find 
it  in  the  reference  section  of  most  good  public  libraries,  or  pur¬ 
chase  a  copy — it’s  expensive  but  indispensable  to  an  organized 
search. 

NEED  A  PHD? 

Q:  I  have  been  in  the  health-care  industry  for  five  years  as  a 
director  of  complex  IT  shops,  and  I  have  an  MBA.  What  are 
your  thoughts  on  the  advantages  of  a  PhD  in  information  sys¬ 
tems?  Is  it  a  plus  or  minus— or  is  it  overkill? 

A:  You  are  in  an  industry  where  many  PhDs  are  routinely 
working  in  drug  discovery,  the  research  and  development 
function,  medical  and  regulatory  affairs,  and  so  on.  Perhaps  a 
PhD  in  information  systems  would  help  you  gain  some  miss¬ 
ing  respect  from  your  user  communities,  and  perhaps  it  would 
make  you  feel  better  about  yourself.  If  so,  then  go  ahead 
with  your  plan,  find  an  appropriate  school  and  just  do  it;  but 
I  doubt  that  a  PhD  is  necessary  for  you  to  do  a  great  job  as 
an  IT  director.  In  fact,  a  PhD  in  most  commercial  and  industrial 
venues  would  by  generalization  flag  you,  perhaps  unjustly,  as 
an  academically  oriented  individual,  one  not  able  to  run  a  fast- 
paced,  high-pressure  IT  shop.  PhDs  are  usually  seen  on  uni¬ 
versity  campuses  and  research  and  development  companies 
that  build  hardware  and  software,  developing  new  and  emerg¬ 
ing  technologies. 


The  transition  from  Big  Five  consulting  to 
corporate  information  technology  is  an  issue 
of  operating  management  experience. 


54  CIO  JUNE  1,  2000  •  www.cio.com 


Who’s  On 


Knowing  the  up -to -the -moment 
answer  to  this  question  is  crucial 
to  anyone  providing  Professional 
Services. 

Account4™  Web-based  Professional 
Services  Automation  software  helps 
you  get  the  right  people  in  the 
right  places  at  the  right  time,  and 
supports  your  business  processes. 
For  example  ... 

Opportunity  Management:  evaluate, 
track,  and  analyze  your  pipeline  to 
maximize  revenue; 

Resource  Management:  optimize  your 
staff’s  utilization  by  balancing  demand 
with  capacity; 

Client  Management:  maximize 
engagement  performance,  and  provide 
your  contacts  with  the  information 
they  need  when  they  want  it  — 
improving  customer  satisfaction; 

Invoice  Management:  create  on-line 
invoices  and  dramatically  reduce  the 
billing  cycle. 

Account4  lets  you  track  time  and 
expenses,  and  share  and  disseminate 
information  on  clients,  consultants, 
engagements,  and  costs  — 
anytime,  anywhere. 


Web-based  software  for 

Professional  Services  Automation 


“PSA  software  users  can  expect  a  3-8%  increase  in  productivity.” 

-  The  Aberdeen  Group 


The  Final  Score 


Productivity  Utilization  Additional 


increase 

increase 

revenue 

Home  Team 

3% 

30  people 

$12M 

Competition 

0 

o 

$0 

Based  on  1000-person  staff,  billable  200  days/year  @  $2000/ day. 


How  would  your  team  score? 

Do  a  quick  calculation  at  www.account4.com. 
Also  get  a  “ Who's  On  The  Bench"  white  paper 
and  free  CD. 


f>\c.c.our\t^-.com 


Career  Counsel 


HOLDING  PATTERN 

Q:  I  am  an  IT  engineering  manager  with  20  years’  IT  experi¬ 
ence  and  five  years'  IT  technical  management  experience.  My 
long-range  goal  is  to  be  a  CTO  for  a  small  or  midsize  high-tech 
company.  I’m  considering  a  job  change  into  a  senior  IT  archi¬ 
tect  position  for  a  large  company  (20,000  employees).  I  would 
not  be  managing  others  in  this  position.  Will  the  lapse  in  man¬ 
agement  hurt  my  chances  of  getting  a  CTO  position?  Would 
continuous  years  of  IT  management  fare  better? 

A:  Since  you  have  already  managed  people,  projects  and  bud¬ 
gets  for  quite  a  few  years,  I  recommend  going  forward  with 
the  senior  IT  architect  position.  First,  functioning  in  a  staff 
role  (it’s  really  very  different  from  line  management)  will  give 
you  the  time  and  experience  to  really  hone  your  collaborative 


Have  a  career  question? 


Visit  our  website  at  www.cio.com/ 
forums/executive/counselor.html  and 
pose  your  own  questions  to  Mark  Polansky. 

relationship  building  and  other  interpersonal  and  communica¬ 
tion  skills  since  these  capabilities  are  often  very  visible  in  a 
staff  position. 

Second,  the  experience  of  focusing  on  technological  issues, 
including  the  application  and  leveraging  of  new  and  emerging 
technologies,  is  a  critical  success  factor  for  your  ultimate  objec¬ 
tive  of  becoming  a  chief  technology  officer.  I  believe  you  will  be 
fine  as  long  as  you  don’t  get  sidetracked  out  of  management  for 
too  long. 

EXECUTIVE  COACHING 

Q:  I  am  director  of  the  information  systems  division,  reporting 
directly  to  the  CEO,  for  a  small  company  (less  than  $20  mil¬ 
lion  in  revenues)  focused  on  the  aerospace  community.  This  is 
my  first  executive-level  job,  and  I  am  currently  seeking  execu¬ 
tive  coaching  to  help  me  with  my  career.  I  have  met  some  oppo¬ 
sition  in  the  company  about  getting  this  kind  of  assistance.  Does 
that  mean  that  they  expect  me  to  fail?  I  have  almost  20  years’ 
experience  in  management  with  17  years  of  IT  background. 
Was  I  out  of  line  to  ask  for  assistance? 

A:  No,  I  am  quite  certain  that  they  don’t  expect  you  to  fail.  It 
is  simply  a  matter  of  resources.  Unfortunately,  smaller  compa¬ 
nies  (and  generally  privately  held  companies  as  well)  have  less 
room  in  the  budget  for  niceties  like  management  training.  They 


also  don’t  have  the  greater  perspective  of  the  need  to  profes¬ 
sionally  develop  their  human  resources  that  larger  organiza¬ 
tions  do.  It’s  just  one  of  the  many  trade-offs  of  big  company 
versus  small  company  decisions  that  many  of  us  have  faced  in 
our  careers. 

CIO  VIRTUOSO 

Q:  I  am  a  22-year-old  IT  director  for  a  small  but  rapidly  grow¬ 
ing  business.  I  created  the  information  technology  department 
and  earned  my  position  by  strategically  planning  and  applying 
technology  to  our  business  operations.  I’ve  developed  our  data¬ 
base,  website,  network  and  data  management.  I  continue  to 
integrate  new  technology  with  our  business  models  by  suc¬ 
cessfully  hiring,  training  and  managing  new  employees  in  the 
IT  profession  to  deploy  our  strategy.  The  pay  has  been  very 
low  compared  with  other  chief  information  officers,  vice  presi¬ 
dents  and  directors. 

Should  my  age  or  lack  of  several  years  of  experience  hold  me 
back  from  trying  to  earn  a  vice  president  or  CIO  title  and 
salary?  I  am  a  major  part  of  the  success  of  the  company,  but 
how  do  I  convince  the  president  that  I  am  vice  president  or  CIO 
material? 

A:  Wow,  you  have  many  accomplishments  and  yet  are  only 
22  years  old.  I’m  impressed,  but  it  sounds  like  the  president 
isn’t — yet — or  at  least  he’s  not  showing  it.  Unfortunately,  your 
age  and  years  of  chronological  experience  have  a  negative 
impact  on  your  compensation  since  the  lack  of  time  and  job 
changes  (internal  or  external)  have  limited  the  number  and 
probably  the  size  of  the  raises  you  have  received  beyond  your 
entry-level  salary. 

A  dramatic  adjustment  may  very  well  be  in  order  to  bring 
your  earnings  up  to  reflect  your  position  and  level  of  respon¬ 
sibility,  and  especially  your  contributions  to  the  enterprise,  not 
to  mention  parity  with  the  market.  Sit  down  with  your  presi¬ 
dent  (get  him  out  to  lunch  or  dinner  if  possible)  and  in  a  firm 
but  positive  way,  ask  him  if  he  is  aware  of  your  achievements. 
Educate  him  regarding  the  role  of  chief  information  officers 
and  what  a  good  CIO  earns  in  today’s  economy.  Have  a  num¬ 
ber  in  mind  in  case  he  asks.  And  be  prepared  to  initiate  a  job 
search  if  he  doesn’t.  K3E3 


Mark  Polansky  is  a  managing  director  and  member  of  the  advanced  tech¬ 
nology  practice  in  the  New  York  City  office  of  Korn/Ferry  International. 
He  has  also  been  recently  named  the  chairman  of  the 
Greater  New  York  Chapter  of  the  Society  for  Information 
Management.  The  web-based  Executive  Career  Coun¬ 
selor  column  (found  on  www.cio.com)  is  edited  by  Web 
Research  Editor  Kathleen  Kotwica.  She  can  be  reached 
at  kkotwica@cio.com. 


56  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  ANDRE  SOUROUJON 


Results 

When  you  bring  in 


The  Technical  Resource  Connection,  Inc. 


to  deliver  software  solutions  to  your  business  problems, 
define  your  enterprise  architecture,  or  build  e-business 
solutions,  be  prepared  for  results. 

The  Results:  We  deliver  what  you  expect. 

On  time.  Within  budget.  Faster.  No  surprises.  Working. 

The  Long-Term  Benefits:  Improved  business. 

More  reliable.  Scalable.  Flexible.  Competitive 

That's  because  TRC  focuses  on 

solving  your  business  problems 
using  our 

SolutionThread™ 
architecture-driven 
software  development  methodology. 

TRC  has  applied  its  methodology  to  architect  and  deliver  a 
variety  of  successful  large-scale  applications,  among  them: 

•  e-business  infrastructures  in  the  real-estate  services, 
insurance,  and  financial  services  industries 

•  product  ordering  systems  in  the  insurance  and 
telecommunications  industries 

•  enterprise  architecture  definitions  in  the  banking, 
financial  services,  and  insurance  industries 

•  trading  systems  in  the  banking  and 
financial  services  industries 

•  customer  care,  work  management  (workflow),  and 
product  distribution  software  in  the  retail,  pharmacy, 
telecommunications,  and  financial  services  industries 


Our  service  offerings  incSude: 

•  Architecture-Driven  Software  Development 

•  Enterprise  Architecture  Definition 

•  Project  Assessments 

•  Technology  Consulting 

•  Training  and  Mentoring 


Our  technical  expertise  includes: 

•  CORBA,  EJB,  MOM,  application  sen/ers  and  other 
middleware  technologies 

•  Java  and  C++ 

•  RDBMS  and  OODBMS 

•  Web  servers,  XML,  XSL 

•  Microsoft  COM+,  MTS,  MSMQ 


For  details  about  TRC’s  SolutionThread™  methodology, 
request  your  FREE  “Guide  to  Architecting  Distributed  Computing”  from  results@trcinc.com 


To  learn  how  The  Technical  Resource  Connection  can  meet  your  expectations — and  get  results — 

visit  www.trcinc.com, 

or  call  1-800-TRC-2992,  ext.  3029# 

For  job  opportunities,  send  resumes  tojobs@trcinc.com. 

12320  Racetrack  Road 
Tampa,  Florida  33626 

The  Technical  Resource  Connection,  Inc.  is  a  Wholly  Owned  Subsidiary  of  Perot  Systems  Corporation 


vjc£ro 


1X3 
&  \ 
V-* 


& 


Jo 


<  V 


What  would  you  do 
update  the  Web 

“I’d  finish  the  transaction 
“I’d  look  at  integrating  new  servers  with  our  legacy  systems. 

“I’d  review  our  site  security  systems.” 

“Vd  stop  hiding  from  marketing  and  customer  service  and  sales  and....” 


CONTENT  MANAGEMENT  should  be  easy.  Up  and  running  without  a  hassle  —  or  IT  overload. 
That’s  what  Eprise  does.  No  client  software.  No  database  to  design.  Just  a  powerful  content  management 
application  that  lets  business  users  create,  update,  and  target  Web-based  content.  After  all,  what  good  is  a 
Web  site  if  it  can’t  deliver  information  immediately.  If  not  sooner.  What  would  you  do  with  your  Web  site  if  you  could? 
Let  us  know.  WWW.EPRISE.COM 


EPRISE' 

mind  your  content 


if  marketing  could 
site  on  its  own? 

engine  implementation.” 


Davenport  On... 


The  Winner’s 

Circle 

If  you  want  your  e-strategy  to  succeed, 
you’d  better  figure  out  what  you  want  to  be 

BY  TOM  DAVENPORT 

CLEARLY,  ONE  of  the  diseases  of  the  Internet  Age  is  hubris.  Symp¬ 
toms  involve  “Cashing  out  quick  before  the  investors  under¬ 
stand  what’s  going  on  here.” 

A  subtler  and  more  interesting  symptom  of  internet  hubris 
is  the  “we  can  have  our  cake  and  eat  it  too”  business  model. 
With  it,  the  thinking  goes,  the  internet  is  such  a  powerful  tool 
that  companies  can  ignore  time-honored  business  choices  and 
have  it  all.  Low  cost  or  good  service?  Consumer  markets  or 
business-to-business?  Companies  have  always  had  to  make 
such  distinctions  based  on  good  business  sense,  and  strategy 
textbooks  have  rationalized  such  decisions  since  Michael  Porter 
was  in  diapers.  Sure,  a  company  can  have  different  business 
models  under  one  corporate  roof,  but  conventional  wisdom 
dictates  that  they  be  segregated  across  different  business  units. 

Now  a  lot  of  organizations  are  feeling  constrained  by  such 
thinking;  they  want  to  simultaneously  adopt  both  alternatives 
within  one  business  unit.  Strategic  focus  no  longer  matters  in 
many  internet  business  models;  all  that  matters  is  being  on  the 
internet  and  having  customers.  Maybe  I’m  just  a  hopeless  relic 
of  the  old  economy,  but  I  still  feel  that  on  many  issues  of  inter¬ 


net  strategy  you’ve  got  to  declare  which  side  you  are  on. 

In  the  business-to-business  world,  many  e-commerce  hubs, 
exchanges  or  networks  are  trying  to  be  all  things  to  all  cus¬ 
tomers.  Are  they  places  to  buy  or  sell  surplus  supply  on  the 
cheap,  or  are  they  going  to  create  tight,  collaborative  relation¬ 
ships  between  buyers  and  sellers?  Are  they  for  hard-core  buying 
or  casual  chatting?  My  sense  is  that  if  you  try  to  do  all  of  these 
things,  you  won’t  do  any  of  them  well.  The  cost  structures, 
processes  and  management  styles  necessary  to  do  one  type  of 
business  well  will  leak  into  areas  in  which  they  don’t  fit.  Despite 
the  miraculous  qualities  of  the  internet,  straddling  business 
models  within  a  business  unit  will  ultimately  lead  to  painful 
splits. 

The  recently  announced  mega-exchange  for  the  Big  Three 
automakers  has  elements — at  least  in  the  aspects  of  its  design 
that  have  been  announced — of  both  cheap  source  for  marginal 


60  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  ROBERT  LITTLEFORD 


Ameritrade 

Make  Trading  Online  As 

Rewarding  As  Possible? 


Online  customer  communications  will 
never  be  the  same.  Kana  is  changing  the  way 
leading  companies  like  Ameritrade  ,  Inc. 
communicate  with  their  customers  forever. 

Kana  offers  a  comprehensive  communi¬ 
cations  solution  for  marketing,  sales  and  service. 
This  allows  e-businesses  to  communicate 
with  their  customers  using  outbound  and 
inbound  e-mail,  Web  self-service,  one-to-one 
realtime  messaging  and  voice  over  the  Internet. 

Offering  unsurpassed  service  and  support, 
systems  integration  and  cost-effective  hosted 
environments,  Kana  has  the  solution  to  meet 
every  online  communication  challenge. 

So  if  you’re  in  the  market  for  a  solution 
that’ll  increase  revenue,  enhance  customer 
loyalty  and  reduce  operating  costs,  follow  the 
lead  of  Ameritrade  and  hundreds  of  other 
successful  e-businesses. 


For  a  FREE  Kana  demo,  visit  our  Web  site  today 


COMPLETE  ONLINE 
CUSTOMER 
COMMUNICATIONS 


O  2(NM>  Kana  ('ommunicanons  Inc.  Kana  is  .1  registered  trademark  of  Kana.  The  Kana  logo  and  Kana 
<  ninmutm  Jtinns  are  trademarks  of  Kana.  All  other  trademarks  are  properties  of  their  respective  holders. 


Davenport  On... 


purchases  and  integrated  core  supplier  market.  The  compa¬ 
nies  expect  tens  of  billions  in  cost  savings,  which  suggests  that 
suppliers  will  be  pitted  against  each  other  to  submit  lowball 
offers.  But  reports  also  suggest  that  some  of  the  exchange’s 
applications  will  include  advanced  planning  and  scheduling, 
demand  forecasting  and  demand  collaboration.  That  suggests 
close  integration  with  suppliers.  Has  it  occurred  to  anyone  in 
Detroit  or  Stuttgart  that  these  purposes  might  not  be  easily 
reconciled? 

It  has  occurred  to  Toyota,  whose  participation  in  the 
exchange  was  actively  sought  by  the  other  three  partners.  But 
in  a  Financial  Times  article  on  the  exchange,  Tadaaki  Jagawa, 


Toyota’s  head  of  procurement,  noted  that,  “Our  parts  are  not 
purchased  through  a  bidding  process.  We  buy  them  by  building 
a  relationship  with  our  suppliers  over  time.”  Analysts  suggest 
that  Toyota’s  close  relationships  with  suppliers  are  critical  both 
to  its  high  quality  levels  and  its  shorter  new  car  development 
cycle  than  those  of  U.S.  or  European  automakers.  Toyota  will 
participate  in  the  exchange,  but  only  on  the  margin:  buying 
nuts  and  bolts  and  office  supplies  through  it.  In  other  words, 
Toyota  views  the  exchange  as  a  place  to  save  a  few  bucks — er, 
yen— -on  stuff  that  really  doesn’t  matter  much  to  its  business. 
Supplier  integration  with  its  business  processes  will  take  place 
not  over  the  internet  but  through  extended  face-to-face  nego¬ 
tiations  and  linkages  between  proprietary  systems. 

One  reason  that  e-networks  need  to  choose  between  low 
price  and  integration  is  that  integration  is  surely  going  to  be 
expensive.  It  took  a  decade  and  hundreds  of  meetings,  for 
example,  for  the  automobile  industry  to  develop  EDI  standards 
and  integrate  with  its  suppliers  using  that  technology.  EDI  is 
sometimes  described  as  an  expensive  technology,  but  its  cost 
pales  in  comparison  to  the  human  costs  of  agreeing  on  infor¬ 
mation  and  process  standards.  Suppliers  can  justifiably  argue 
that  they  are  supposed  to  post  rock-bottom  prices  to  get  busi¬ 
ness  on  an  exchange,  while  having  to  spend  megabucks  on  inte¬ 
grating  with  car  companies.  The  automakers  will  have  to  work 
closely  with  suppliers  if  they’re  going  to  meet  their  goals  of 
rapid  new  car  development  and  build-to-order  manufacturing 
processes,  so  they  won’t  be  able  to  buy  from  the  lowest-price 
supplier  on  the  exchange.  I’m  predicting  that  the  U.S.  and  Ger¬ 
man  companies  involved  in  the  exchange  will  end  up  buying 
only  commodity  stuff,  just  as  Toyota  plans  to  do. 


The  Vertizontal  Network 

Another  “have  your  cake  and  eat  it  too”  situation  can  be  found 
in  the  race  to  make  vertical  networks  horizontal,  and  at  the 
same  time  to  augment  e-content  and  e-community  with  e-com- 
merce.  Nobody’s  satisfied  with  their  little  niches.  The  trend 
today  is  to  expand  single  vertical  markets  into  multiple  ones. 
VerticalNet  is  the  paradigm  of  this  strategy,  having  expanded 
into  more  than  50  different  industries.  That  worked  fine  when 
all  it  offered  was  trade  publication  content  and  advertising, 
which  was  its  original  business  model.  But  then  it  became  clear 
that  all  those  industries  would  eventually  be  offered  e-com- 
merce  transactions  through  exchanges,  and  VerticalNet  needed 

to  grow.  Transaction-based  revenues  are 
often  more  lucrative  than  relying  on 
advertising.  However,  it’s  going  to  be 
tough  for  VerticalNet  to  convince  con¬ 
tent  viewers  to  become  exchange  partic¬ 
ipants.  Readers  of  SolidWaste.com,  for 
example,  have  often  built  up  relation¬ 
ships  with  industry  colleagues  over  years 
at  trade  shows,  golf  games  and  other  face-to-face  settings. 
Moving  the  relationships  online  may  simply  not  work,  or  may 
take  too  long  for  VerticalNet  to  profit  from  them. 

Other  companies  that  previously  specialized  in  one  kind  of 
product  or  industry  are  expanding.  Chemdex,  which  sells  lab¬ 
oratory  equipment  online  to  the  life  sciences  industry,  has 
announced  that  it  will  diversify  into  other  types  of  products  and 
markets.  In  fact,  the  company  is  no  longer  Chemdex — that’s 
just  one  of  its  offerings- — but  Ventro,  a  general  provider  of 
B-to-B  marketplaces.  Why  make  the  shift?  Because  there  are 
only  so  many  dollars  one  can  wring  out  of  distributing  beakers 
and  Bunsen  burners. 

But  what  do  C'hemdex’s  customers  lose  when  Ventro  goes 
multi  vertical?  Perhaps  nothing  initially.  But  eventually  the  peo¬ 
ple  who  specialized  in  the  laboratory  and  life  sciences  markets 
will  be  asked  to  focus  on  other  kinds  of  markets  as  well.  The 
knowledge  of  industry  people,  processes  and  products  will  get 
watered  down.  Wall  Street  analysts  may  applaud  such  diversi¬ 
fication,  but  I  expect  that  over  the  long  run  customers  will 
decry  it. 

In  short,  this  is  yet  another  area  in  which  the  rules  of  e- 
commerce  will  converge  with  the  rules  of  commerce:  Stick  to 
your  knitting.  Don’t  get  stuck  in  the  middle.  Strategy  is  about 
choices.  Isn’t  it  great  that  we  can  get  new  life  out  of  these  old 
business  cliches  by  applying  them  to  electronic 
commerce?  BH 


Tom  Davenport  pontificates  at  both  Andersen  Consult¬ 
ing's  Institute  for  Strategic  Change  and  Babson  College. 
He  welcomes  reader  comments  at  davenport@cio.com. 


Despite  the  miraculous  qualities  of  the  internet, 
straddling  business  models  within  a  business  unit 
will  ultimately  lead  to  painful  splits. 


62  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  FURNALD/GRAY 


□o  You  Want  To 

Max  Out 

Your  e-Busines! 

Opportunities? 


Want  to  use  the  Internet  to  connect  branch  offices  and  reduce  communications 


costs?  Groovy.  Want  to  secure  your  corporate  network  and  keep  confidential 


information  confidential?  Right  on.  Want  to  make  sure  your  customers  are  who 


they  say  they  are  and  take  advantage  of  new  ways  to  do  e-business?  Far  out, 


With  Cylink  you  can  do  all  that  and  more 


Because  for  more  than  16  years  we've  been 


developing  security  solutions  for  some  of  the 


largest  and  most  respected  companies  in  the  world 


Solutions  that  are  easy  to  implement  and  easy  to  manage  from  anywhere  on  your 


network  regardless  of  type  or  technology. 


So  don't  let  network  security  keep  you  from  doing  your  e-business  thing 


Max  out  your  e-business  opportunities.  And  do  what  you  want  to  do.  With  Cylink 


Securing  e-business 


Introducing  a  solution  for  increased  peace  of 
mind  and  reliability:  APC  Symmetra®  Power 
Array™  with  New  Remote  Monitoring  Service. 

Since  becoming  the  world's  first  Power  Array  a  few  years  ago,  Symmetra 
Power  Array  N+1  redundant  technology  has  become  a  proven  industry  stan¬ 
dard  in  high  availability  and  power  protection.  Companies  that  demand  near 
100%  uptime  like  IBM,  ZDTV  and  Arthur  Andersen,  now  trust  their  uptime 
needs  to  Symmetra  Power  Array  and  APC. 

For  increased  reliability  and  peace  of  mind,  APC  introduces  its  new  Remote 
Monitoring  Service.  APC  will  monitor  your  UPSs  while  you  worry  about 
your  business.  If  there's  a  problem,  we  let  you  know,  and  if  it's  necessary, 
we'll  even  send  a  qualified  APC  technician  to  fix  it  on-site. 

APC's  reliable  service  watches  over  your  system  24  x  7  to  monitor  high  avail¬ 
ability  APC  products  like  Symmetra  Power  Array,  Silcon™  DP300E,  Matrix- 
UPS®,  Smart-UPS®,  and  a  wide  range  of  accessories. 


"Not  having  a  Symmetra  in  place  would 
have  resulted  in  lost  data,  corrupted  hard 
drives  and  lost  time  to  recover.  The 
Symmetra  system  has  more  than  paid  for 
itself  during  this  one  outage." 


Bob  Lesher  and  Charlie  Bise, 
Information  Technology, 

Exel  Logistics 


was  recently  awarded 
US  Patent  *5,982,652 


Enter  to  WIN  A  FREE  Symmetra  Power  Array  along  with 

To  order:  Visit  http://promo.apcc.com  Key  Code  t503z 


©2000  American  Power  Conversion.  All  Trademarks  are  the  property  of  their  owners.  SV1  B0ES-USd  •  PowerFax:  (800)  347-FAXX  •  E-mail:  apcinfo@apcc.com  •  132  Fairgrounds  Road,  West  Kingston,  Rl  02892  USA 


Enter  to  WIN  A  FREE 
Symmetra  Power  Array 
along  with  a  year  of 
FREE  Remote 
Monitoring  Service. 

All  entrants  will  receive  a  FREE  Power 
Availability  Kit 

Just  mail  or  fax  this  completed  coupon  or 
contact  APC  for  a  chance  to  win  a  FREE 
Symmetra  Power  Array  with  Remote  Monitoring. 
Better  yet,  order  it  today  at  the  APC  Web  site! 


Key  Code 

http://promo.apcc.com  tso 3z 

(888)  289-APCC  x1522  •  FAX:  (401 )  788-2797 


Legendary  Reliability’" 


□  YES!  Enter  me  to  win  a  FREE  Symmetra 

Power  Array  with  one  year  of  Remote 
Monitoring  Service.  Please  send  me 
my  FREE  Power  Availability  Kit. 

□  NO,  I'm  not  interested  at  this  time  but 

please  add  me  to  your  mailing  list. 


Name: 


Enter  to 
WIN  A  FREE 
Symmetra® 
Power  Array 


Key  Code 

t503z 


Title: _ Company:  _ 

Address: _ 

City/Town: _ State: _ Zip: _ Country 

Phone: _ 


Brand  of  UPS  used? 


t 


Brand  of  PC  used?  _ #  _ 

Brand  of  Servers  used? _ #  _ 

©2000  APC.  All  trademarks  are  the  property  of  their  owners.  SY1B0EB-US_2c  •  E-mail  apcinfo@apcc.com  •  132  Fairgrounds  Road.  West  Kingston.  Rl  02892  USA 


NO  POSTAGE 
NECESSARY 
IF  MAILED 
IN  THE 

UNITED  STATES 


BUSINESS  REPLY  MAIL 

FIRST-CLASS  MAIL  PERMIT  NO.  36  WEST  KINGSTON  Rl 
POSTAGE  WILL  BE  PAID  BY  ADDRESSEE 


KEY  CODE:  t503z 
Department:  B 
132  FAIRGROUNDS  ROAD 
PO  BOX  278 

WEST  KINGSTON  Rl  02892-9920 


mu 


How  to  Contact  APC 

Call:  (888)  289-APCC 

use  the  extension  on  the  reverse  side 

Fax:  (401)  788-2797 

Visit  http://promo.apcc.com 

use  the  key  code  on  the  reverse  side 


Legendary  Reliability 


a 

ft: 

ft 

I 

1 

1 

1 

I 

I 

I 

I 


Symmetra  Power  Array's  proven 
reliability  provides  the  highest 
availability  for  today's  businesses 


•  N+1  redundancy  design  assures  continuous 
availability  -  If  a  module  fails,  the  others 
instantly  begin  supporting  the  full  load. 


•  Scalable  power  -  Additional  4  kVA  modules 
can  be  added  to  expand  to  16  kVA  of  power 
capacity  (4  unit  frame  is  expandable  to  8  kVA) 


•  Serviceable  while  load  is  up  and  running  - 
Additional  battery  modules  increase  runtime 
and  all  the  modules  are  hot  swappable, 
meaning  no  downtime. 


Enhance  the  availability  of  your  business 
with  APC  accesories: 


A  PC  MasterS witch™  can 
save  you  time  and  money  m 
by  helping  your  staff  to 
manage  power  proactively. 


APC  was  chosen  by  PC  Magazine  as  one 
of  the  "Top  100  Technology  Companies 
That  Are  Changing  The  World"  (10/99). 


Remote  Monitoring 
System  is  the  key  to  your 
complete  peace  of  mind 

•  Immediate  Notification 
Customers  are  informed  of  events  via  phone, 
paging,  and/or  E-mail. 

•  Immediate  Response 

With  an  APC  On-Site  service  contract,  APC 
can  ensure  that  our  field  service  technician 
arrives  at  the  site  with  the  equipment  and 
knowledge  to  service  the  UPS  the  first  time. 

•  Monthly  Alarm  Reports 

Each  alarm  occurrence  and  duration  is  tracked, 
recorded,  and  summarized  in  a  report. 

•  Environmental  Surveillance 

In  addition  to  monitoring  the  UPS,  APC  is 
also  monitoring  the  ambient  room  tempera¬ 
ture  and  humidity  where  the  UPS  is  located. 

•  Web-based  Customized  Escalation 
Each  event  response  is  defined  by  the 
customer  and  tailored  to  their  needs. 


Trust  your  system's  uptime  to  APC.  Our  tech¬ 
nology  grows  with  your  business  and  can 
help  power  protect  your  new  applications  as 
you  roll  them  out.  Contact  APC  today  and  let 
APC's  Legendary  Reliability™  work  for  you. 


Legendary  Reliability 


APCC 

A  Nasdaq-100 
Company 


a  year  of  FREE  Remote  Monitoring  Service. 

•  Call  888-289-APCC  xl  522  •  Fa*  401-788-2797 


Total  Leadership 


Inspiring 

Minds 

Part  of  being  a  great  leader  is  finding 
ways  to  inspire  those  around  you 

BY  PATRICIA  WALLINGTON 

“Their’s  not  to  make  reply, 

Their’s  not  to  reason  why, 

Their’s  but  to  do  and  die: 

Into  the  valley  of  Death 
Rode  the  six  hundred.  ” 

-from  The  Charge  of  the  Light  Brigade,  by 
Alfred  Lord  Tennyson 

My  fascination  with  leadership  began  when  I  had  to  study  this 
poem  as  a  child.  I  could  never  understand  why  the  six  hun¬ 
dred  followed  their  leader  knowing  they  were  facing  sure 
death.  I  asked  why  so  many  times  my  teacher  sent  home  a 
note  saying  I  was  being  disruptive  in  class.  Fortunately,  I  was 
not  dissuaded  from  my  quest  to  understand  great  leaders. 

Think  of  some  of  the  inspirational  leaders  of  the  past: 
Mahatma  Gandhi,  Winston  Churchill,  George  Patton,  Mother 
Teresa.  What  did  they  have  in  common?  Passion  for  a  cause, 
commitment,  vision,  energy,  courage.  Make  your  own  list.  One 
of  the  best  ways  to  become  an  inspirational  leader  is  to  study 
those  who  are.  Better  yet,  work  for  one  and  learn  from  her. 
Early  in  my  career  I  had  two  experiences  with  what  I’ll  call 


inspirational  leaders.  One  remains  my  favorite  boss.  First,  he 
was  always  accessible.  No  matter  how  busy  he  was,  he  made 
time  for  me.  To  me,  it  meant  I  mattered.  Second,  he  never 
solved  my  problems.  Instead,  he  gave  me  guidance  in  the  form 
of  principles  that  could  be  used  over  and  over  again  for  dif¬ 
ferent  situations.  Some  examples:  “Kill  your  enemy  with  kind¬ 
ness”;  “Always  take  the  high  road — in  the  long  run,  it  is  the 
winning  strategy”;  “Win  the  war,  not  the  battle.”  Third,  he 
encouraged  me  by  praising  my  strengths.  It  was  up  to  me  to  use  5 
them  to  succeed.  Last,  and  maybe  most  important,  he  “lifted  8 

XL 

me  up.”  He  made  me  feel  I  could  do  anything.  Isn’t  that  what  | 
inspiration  is  all  about? 

Here  are  some  characteristics  to  emulate  if  you  want  to  5 
become  an  inspirational  leader:  ° 

ex 

i — 

00 

=5 

Passion  and  Vision:  People  are  drawn  to  those  who  have  a  =! 


66  CIO  JUNE  1.  2000  •  www.cio.com 


e-business 


It  takes  a  powerful 


transactions  per  hour. 

That’s  the  software 

'8WI  makes 


IBM,  the  e-business  logo  and  Software  is  the  soul  of  e-business,  are  trademarks  of  International  Business  Machines  Corporation  in  the  United  States  and/or  other  countries.  ©  2000  IBM  Corporation  All  rights  reserved 


— 

*  w-ifi 

WfM 

m 

_ 4 

{ 1 

73BR 

ppK  *°/a§ 

r  pm 

#**  * 

t  .11 

1|  ISi 

38 

rfl  §f 

W  | 

s  *ii  - 1 

.. I 

mb  i 

* 

Klv  4-:  “%SHi 

Total  Leadership 


vision  and  a  passion  for  their  cause.  In  our  field  this  should 
be  an  easy  one.  The  mix  of  the  new  technology  and  the  tran¬ 
sitional  state  of  business  as  we  move  from  the  old  economy  into 
the  new  economy  makes  exciting  opportunities  easy  picking. 
If  you  work  in  your  own  areas  of  deep  interest,  the  passion 
surfaces  with  no  difficulty.  Then  create  the  vision  for  others  to 
see.  Finding  the  words,  drawing  the  pictures  that  capture  the 
imagination  is  a  skill  that  can  be  learned  and  practiced.  Think 
of  famous  inspirational  words  that  still  reverberate  today,  such 
as  Martin  Luther  King’s  “I  have  a  dream....” 

Will  and  Determination:  Some  people  commit  to  accomplish, 
others  try  to  accomplish,  but  great  leaders  intend  to  accom¬ 
plish.  They  have  a  will  and  determination  that  knows  no 


charisma — their  social,  extroverted  personalities  draw  people 
to  them  like  a  magnet.  Either  way,  great  leaders  manage  to 
find  a  common  ground  with  people  and  build  rapport. 

Authenticity:  Say  what  you  mean;  mean  what  you  say.  Meet 
commitments.  Be  predictable.  Set  the  example  of  what  you 
want  people  to  be. 

Connectedness:  Inspiring  leaders  connect  with  ideas  by  lis¬ 
tening  intently  with  open  minds  and  learning  from  everyone. 
They  connect  with  people  by  looking  at  them  directly.  They 
see  people  for  who  they  are  and  what  they  know — not  what 
they  are  and  who  they  know.  Finally,  they  connect  with  results 
by  getting  things  done. 


The  best  leaders  can  readily  describe  their  failures; 
only  the  mediocre  have  none  to  remember. 


boundaries.  No  matter  the  number  of  distractions,  they  keep 
their  eye  on  the  target.  They  see  obstacles  as  only  those  things 
you  need  to  get  past  to  reach  the  target. 

Courage:  Aristotle  believed  that  courage  is  the  first  of  all  virtues 
because  it  makes  the  others  possible.  There  is  an  element  of  per¬ 
sonal  risk-taking  in  the  deeds  of  great  leaders.  They  do  not  have 
a  “what’s  in  it  for  me”  attitude.  They  take  on  the  “big  idea.” 
There  is  a  willingness  to  take  a  stand  even  if  it  is  controversial 
or  politically  incorrect.  With  this  goes  the  willingness  to  take 
responsibility  and  accountability  for  results. 

Confidence:  Fear  of  failure  is  not  an  attribute  of  inspiring  lead¬ 
ers.  They  take  failure  in  stride — not  satisfied  that  it  occurred, 
but  not  devastated,  either.  The  best  leaders  can  readily  describe 
their  failures;  only  the  mediocre  have  none  to  remember.  Learn 
from  these  great  leaders  and  try  again.  Have  the  confidence  to 
make  the  big  decisions  and  move  on. 

Caring:  The  ability  to  empathize  with  others  and  understand 
their  individual  motivations  is  a  hallmark  of  leadership.  Great 
leaders  find  many  ways  to  meet  people’s  needs.  They  care 
enough  to  expect  a  lot  from  their  people,  and  they  believe  in 
them.  They  engender  tremendous  loyalty  as  a  result.  When 
someone  cares  about  you  personally  it  creates  a  solid  bond. 

Charisma:  There  are  leaders  with  low-key  personalities  who 
inspire  great  devotion,  and  there  are  also  many  who  have  great 


You  might  think  some  people  are 
born  leaders.  But  there  are  surely 
days  when  even  the  greatest  are  nei¬ 
ther  inspired  nor  inspiring.  On  the 
flip  side,  sometimes  events  raise  peo¬ 
ple  to  a  greatness  they’ve  never 
shown  and  may  never  exhibit  again. 
One  example  I’ve  seen  was  in  a  large  company  undertaking  a 
huge,  risky  project.  Most  times  in  this  company  people  would 
avoid  this  type  of  project  because  of  the  risk  of  failure.  In  this 
case,  though,  the  project  leader  was  so  passionate  about  the 
possibilities  and  the  positive  outcomes  that  he  created  a  sort 
of  mystique  around  this  project.  Others  began  to  see  it  as  a 
chance  of  a  lifetime.  Before  you  knew  it,  people  were  volun¬ 
teering  right  and  left.  Needless  to  say,  it  was  a  huge  success. 

What  raised  this  project  leader  to  the  level  of  greatness  in 
this  instance?  His  real  commitment  to  the  outcome?  His  abil¬ 
ity  to  see  the  vision?  His  determination  to  get  it  done?  All  of 
the  above.  Can  he  sustain  this  inspirational  leadership?  That’s 
up  to  him. 

And  it  is  up  to  you.  Try  to  work  for  an  inspiring  leader,  try 
even  harder  to  become  one  and  to  give  back  to  the  profession 
by  developing  new  ones.  The  opportunities  are  bountiful. 
There  is  such  a  body  of  knowledge  resident  in  this  commu¬ 
nity,  such  a  creative  force,  so  many  big  ideas  waiting  to  be 
championed.  QE1 


Send  your  own  tales  of  inspiration  or  other  thoughts  about  our  ongoing 
Total  Leadership  column  to  leadership@cio.com. 

Before  retiring  in  1999,  Patricia  Wallington  was  corpo¬ 
rate  vice  president  and  CIO  at  Xerox  Corp.  In  1997, 

Wallington,  now  president  of  CIO  Associates  based  in 
Sarasota,  Fla.,  was  inducted  into  the  Women  in  Science 
and  Technology  Hall  of  Fame  and  named  by  CIO  one 
of  the  12  most  influential  IT  executives  of  the  decade. 


6  8 


CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BV  FURNALD/GRAY 


e-business 


IBM,  the  e-business  logo  and  Software  is  the  soul  of  e-business,  are  trademarks  of  International  Business  Machines  Corporation  in  the  United  States  and/or  other  countries.  ©2000  IBM  Corporation.  All  nghts  reserved. 


1» 

1 

|8*1 

It  takes  powerful 

software 

to  translate  customer 

expectations 

into  production 

requirements. 

That’s  the  software 

IBM  makes. 


All  rights  reserved. 


1  • 

*  gH^iB  r«M 

aw  'Xjflftj--:* .  jPfc 

w  -T^  jssBB. 

'f.4?  rn^K 

'SSB 

!  »  % 

*  /~S||iflr" . 

,  .  ft  ;5rft-  f«  m  — -  —  ■  • 

k  Jl^B 

$9  * 

«  *fc.  rp  'j'  ’  '•V|v 

~  ?  V  :  '  ' '  jjliX'  ' 

$&&  ,B H  «  J'^qepS 

w+_  ^  32piP 

BT  r 

|SJf  ft 

irft  *  **" 

f^K  «X 

fHM  '-MH 

®Hr 

Sr 

Hfe.  *»* 

1 

jj^ft  ^ 

® 

r  r^jJRl 

raft  ftSS^^S  :wiiBt 

e-busii«!ss 

P0  fttaKHra 

■  ^4HHW  ^  .1 

a*-.  5  «  ft  j 

1  £  Jl 

’If  j 

lit  !!!!-•  t 

•'***.  *  *!£  ^  .'! 

j  ■ 

Sfe.'  'ate  .  •  **&■  -- 

5p*  *  Vftfc  ■  "5*.  -»*•*-  1 

K  X<  I  *  1 

f  ■*■  VI 

TBpsi 

S  * 

p 

r 

5gj#Ut*  .  -^te 

f  f,  . 

!•  ll*f 

**»  1 

ti  i 

®s*  ■«*»“  XX'  .v 

r:t<»  -  ft 

4  of  * 

:a 

i  "ft 

4 

i 


New  data  management  software 
from  IBM  can  help  you  leverage  all  the  information  resources 
in  your  business  as  never  before.  Underline  all.  Now,  for  the 
first  time,  you  can  build  a  simplified,  unified  platform  for  all 
your  customer  relationship,  ERP,  content  management  and 
business  intelligence  applications.  One  that’s  as  diverse  as 
the  tools  and  information  sources  your  people  use.  And  as 
tight  as  the  rivets  on  a  pair  of  jeans. 


Software  *  the  soul  ot  e-business 


IBM  Enterprise  Information  Portal  gives  users  a 
single,  familiar  point  of  access  to  any  and  all 
information  that  is  relevant  to  the  job  at  hand.  No 
matter  what  form  the  original  content  is  in  or  where 
it  resides,  they  can  find  it,  use  it  and  put  it  to  work. 

IBM  Content  Manager  integrates  storage,  search 
and  distribution  of  business  information  in  any 
form.  So  you  can  create  unified  files,  company¬ 
wide  archives  of  computer  output  and  fingertip 
access  for  a  world  of  users  on  a  world  of  networks. 


DB2®  OLAP  Server™  provides  fast  answers  to  hard 
questions  by  letting  users  explore  data  in  new  ways. 
Built-in  financial  and  statistical  functions  make 
multidimensional  analyses  a  snap  for  managers. 
And  implementation  faster  and  easier  for  you. 

The  new  DB2  Universal  Database™ version  7  builds 
in  more  support  for  today’s  most  powerful  analytic 
applications  than  any  other  Web  database.  So  you 
have  less  to  integrate  -  and  a  smarter  e-business 
platform  from  the  start. 


Seeing  is  believing.  See  how  IBM  software  helps  you  capture,  manage,  analyze  and  exploit  more  of  the  information 
flowing  into  your  business.  For  case  histories  in  26  industries,  visit  us  at  www.ibm.com/software/soul/leverage 


‘Just  because  someone  has  been  arrestei 
hacking  doesn’t  mean  he’s  a  criminal,”  s 
convicted  hacker  KEVIN  MITNICK. 


*  Tc  .  .  ,y  . i 


Cover  Story  |  Security 


Reader  ROI 


Learn  why  hiring 
hackers  requires 
careful  consideration 

See  how  some  companies 
are  growing  their  own 
hackers 

Discover  what  skills 
CIOs  should  look  for  in 
security  partners 


igl! 


What  do  you  get  when  you  hire  a  hacker  to  solve  your 
security  woes?  If  you’re  not  careful,  you  can  get  more 
than  you  bargained  for.  Here’s  how  to  do  it  right. 


wnw.cio.com  •  JUNE  1,  2000  CIO  73 


AFTER  ATTENDING  ERNST  &  YOUNG’S  “EXTREME 


HACKING”  COURSE,  RICKY  SOLER, 
INFORMATION  SECURITY  ANALYST  WITH 

FIDUCIARY  TRUST,  WAS  SURPRISED  TO  LEARN 
HOW  EASY  HACKING  REALLY  IS. 


Cover  Story  |  Security 

All  the  hackers  had  to  go  on  were  five  innocuous  e-mail  messages.  Within 
four  hours,  they  had  taken  control  of  their  target’s  bank  account,  changed 
his  password  and  locked  him  out.  They  had  also  acquired  his  credit 
card  numbers,  the  details  of  his  driving  record  and  his  salary  to  the 
penny.  For  the  coup  de  grace,  they  infiltrated  his  office  and  left  a  puck¬ 
ish  note  on  his  desk:  “Hi  Matt,  from  your  friends  at  Jaws." 


Luckily  for  this  target,  Matthew  McClearn,  these  hackers  were  invited 
guests  and  not  intruders.  Part  of  a  so-called  penetration  testing  team  for 
Calgary,  Alberta-based  Jaws  Technologies,  they’d  been  challenged  by 
McClearn  and  his  employer,  the  Calgary  Herald,  to  take  the  five  e-mails 
and  learn  as  much  about  the  reporter  as  they  could  in  a  week.  Using  a 
combination  of  technical  skill  and  social  engineering  (the  art  of  persuading 


people  to  give  out  sensitive  information),  the  Jaws  team  rapidly  created 
a  file  of  information  on  McClearn.  In  addition  to  the  data  above,  the  file 
contained  printouts  of  all  his  bank  transactions  for  the  past  few  months 
as  well  as  the  names  of  friends,  family  members  and  colleagues,  who  in 
turn  could  have  been  targeted  by  real  intruders.  In  the  wrong  hands,  this 
situation  could  have  been  a  consumer  and  corporate  security  nightmare. 


www.cio.com  •  JUNE  1,  2000  CIO  75 


Cover  Story  |  Security 

While  not  a  new  trend,  penetration  testing,  or  testing  security 
from  the  perspective  of  a  would-be  intruder,  has  gained  significant 
appeal  in  the  wake  of  recent  attacks  on  high-profile  companies  like 
Yahoo  and  CNN.  Long-standing  fears  about  security  vulnerabilities 
have  been  brought  uncomfortably  close  to  the  surface  for  CIOs  and 
the  executive  boards  to  which  they  answer,  and  the  realization  that 
there  is  no  such  thing  as  100  percent  security  has  companies  look¬ 
ing  for  any  edge  they  can  get.  As  soon  as  security  holes  are  found 
and  patched,  new  ones  appear,  and  while  the  IT  departments  of  many 
corporations  are  perpetually  understaffed,  hackers,  crackers,  sneakers 
and  phreakers  (see  “Cast  of  Characters,”  Page  84)  seem  to  prosper 
and  proliferate.  To  mix  a  metaphor,  desperate  times  make  for  strange 
bedfellows,  and  CIOs  are  forging  some  unconventional  alliances  in 
their  mission  to  bolster  corporate  security. 

Take  for  example,  Kevin  Mitnick,  the  infamous  36-year-old  hacker 
who  served  five  years  in  federal  prison  for  breaking  into  the  computer 
systems  of  some  of  the  nation’s  biggest  businesses  (see  “Conversation 
with  Kevin  Mitnick,”  this  page).  Since  his  release  from  prison  earlier 
this  year,  Mitnick’s  future  as  a  security  consultant  appears  to  be  quite 
bright.  In  March,  he  met  with  the  Senate’s  Governmental  Affairs 
Committee  to  advise  it  on  how  easy  it  is  to  break  through  govern¬ 
ment  and  corporate  security  systems.  And  at  a  recent  CIO  conference, 
31  percent  of  the  191  information  executives  said  they  would  hire 
Mitnick  to  advise  them  on  security  preparedness  after  he  meets  the 
terms  of  his  three-year  parole  (which  bars  him  from  using  a  computer, 
cellular  phone  or  any  device  with  an  internet  connection). 

The  reasoning  behind  this  is  quite  simple,  according  to  Mitnick. 
“I  have  real-world  experience  circumventing  security  measures,”  he 
says.  “And  that  might  be  more  attractive  [to  a  CIO]  than  hiring  some¬ 
body  right  out  of  school  who  has  a  degree  in  information  security 
but  no  practical  experience.  Companies  are  more  interested  in  expe¬ 
rience  than  education.” 

That  kind  of  real-world  experience  can  also  be  found  at  the  various 
security  vendors,  many  of  which  claim  to  employ  former  hackers, 
reformed  hackers  or  ethical  hackers.  But  what  differentiates  the 
hacker  working  for  a  security  vendor  from  the  pasty-faced,  teenage 
loner  orchestrating  hacks  from  his  parents’  basement?  In  some  cases, 
not  a  lot,  and  before  hiring  a  hacker  or  a  security  company  that 
employs  hackers,  CIOs  have  to  be  prepared  to  ask  the  right  questions. 
“Many  companies  feel  that  somehow  a  hacker  is  adding  value,” 
says  Mike  Higgins,  president  and  cofounder  of  Alexandria,  Va.-based 
Para-Protect  Services.  “What  they  don’t  understand  is  that  they  have 
a  tiger  by  the  tail.” 

MEETTHECAST 

Before  weighing  the  pros  and  cons  of  hiring  a  hacker,  let’s  first  clarify 
what  we  mean  by  hacker.  In  the  multilayered  social  strata  of  the  under¬ 
ground,  the  term  differs  greatly  from  the  way  it’s  used  in  the  main¬ 
stream  media.  To  be  called  a  hacker  does  not  suggest  that  one  is  a 
criminal;  it  simply  connotes  a  level  of  skill  and  a  curiosity  to  explore  sys- 


Kevin  Mitnick,  perhaps  the  nation's  most  notorious 
hacker,  talked  to  us  recently  about  hackers,  corporate 
security  and  where  companies  are  most  vulnerable 

CIO:  What  should  CIOs  consider  before  hiring  hackers? 
Mitnick:  Just  because  somebody  is  a  hacker  doesn’t  mean 
he  has  the  skill  set  to  do  the  job.  A  hacker  might  be  really 
good  at  getting  through  security  measures  on  a  Windows  NT 
box  but  not  good  at  creating  policies  and  procedures  to 
protect  a  company. 

CIO:  What’s  your  opinion  of  the  perpetrators  of  the 
recent  denial-of-service  attacks? 

Mitnick:  When  the  media  labels  those  individuals  as  hack¬ 
ers,  it  distorts  the  definition  and  gives  hackers  a  bad  name. 
You  know,  it’s  interesting,  Steve  Jobs  and  Steve  Wozniack 
started  off  as  hackers;  that’s  how  they  obtained  their  skills. 
Yet  they  weren't  people  who  were  looking  to  do  damage. 

CIO:  How  vulnerable  to  hacking  are  the  majority  of 
companies? 

Mitnick:  Given  the  sufficient  resources,  time  and  money,  any 
computer  system  or  network  is  vulnerable.  CIOs  should 
increase  security  only  to  the  point  that  it  is  cost  effective, 
enough  to  drive  the  hacker  on  to  the  next  person.  It’s  like 
the  security  of  putting  The  Club  on  the  steering  wheel. 
Somebody  could  still  break  into  the  car,  but  it’s  probably 
easier  to  move  on  to  the  next  one. 

CIO:  Should  CIOs  be  wary  of  individuals  with  computer- 
related  criminal  records? 

Mitnick:  Just  because  someone  has  been  arrested  for  hack¬ 
ing,  doesn’t  mean  he  is  a  criminal.  [The  offense]  could  have 
been  very  benign.  He  could  be  a  hacker  who  worked  in  a 
bank  and  circumvented  money  to  an  account  to  steal  it,  or 
he  could  just  be  a  computer  enthusiast  circumventing  secu¬ 
rity  for  other  purposes,  not  to  cause  harm. 

CIO:  What  should  CIOs  worry  most  about  in  their  security 
infrastructures? 

Mitnick:  The  weakest  link  in  the  chain  is  always  the  human 
element.  You  can  have  the  newest  security  tools  to  protect 
your  technology,  but  in  the  end,  if  you  have  a  $7-  or  $8-per- 
hour  person  using  the  equipment,  that  can  be  exploited  by 
a  hacker.  The  less  knowledgeable  the  people  are,  the  easier 
it  is  [for  hackers  to  exploit  them]. 

-D.  Duffy 


7  6  CIO  JUNE  1,  2000 


www.cio.com 


©Agilent Technologies,  Inc.  2000 


di 


made  real. 


jams.  Internet  interruptions.  Drops.  Crashes. 
Seems  like  it's  always  rush  hour  out  there. 
But  with  Agilent  systems  and  technologies, 
the  world's  major  communications  networks 
move  faster,  handle  more,  avoid  trouble  and 


merge  effortlessly.  Happy  motoring. 


;y\..  Agilent  Technologies 

Innovating  the  HP  Way 

Agilent  Technologies  is  a  new  company 
comprised  of  the  former  Hewlett-Packard 
test  and  measurement,  chemical  analysis, 
semiconductor  components  and  medical 
products  businesses,  www.agilent.com 


When  H  Comes 


eTrust  Can  Pro 


It’s  that  sinking  feeling  in  your  stomach.  That 
look  your  face  makes  every  time  you  read  a 
story  about  a  disastrous  corporate  security 
breach.  It’s  that  nagging  fear  that  won’t  go 
away  no  matter  how  many  times  you  tell 
yourself  there’s  nothing  to  worry  about. 
Because  there  is,  security  is  the  number  one 
concern  of  every  IT  professional  for  good  rea¬ 
son.  The  good  news  is  that  there’s  a  proven 
solution  you  can  trust. 


comes  with  putting  your  business  on  the  Web 
is  all  the  risk  that  goes  with  it. 

Undetected  attacks  can  strike  at  any  time, 
from  anywhere,  in  a  mind-boggling  variety 
of  forms.  Most  sites  can't  even  track  every 
attempt.  And  new  threats  are  developed  every 
day,  all  over  the  world. 

Without  the  right  protection,  eCompanies 
risk  losing  everything:  data,  customers, 
revenue,  and  more. 


on  extranets  and  websites,  as  well  as  their 
supporting  enterprise-wide  assets — all  nee 
to  be  secured.  Protecting  the  integrity  and 
availability  of 


A  Simple  Solution  id  Your  Most 
Complicated  Challenge 

Online  business  through  eCommerce,  corpo¬ 
rate  intranets,  partner-to-partner  transactions 


intranet  infor¬ 
mation  is  critical 
to  all  organiza¬ 
tions. 

Web-enabled 
business  appli¬ 
cations  open  up 
all  of  your  back¬ 
end  and  legacy 
systems  to  the 
world. 

Unfortunately, 
in  the  race  to 
become  Web- 


cTrust  Security  Suite 

•  Access  Control 

•  Administration 

•  Single  Sign-On 

•  Firewall 

•  Content  Inspection 

•  Intrusion  Detection 

•  Policy  Compliance 

•  Audit 

•  Virtual  Private  Network 

•  Encryption 

•  Directory 

•  OCSPro 

•  Anti-Virus 


Without  Bullet-Proof  Security, 
Successful  eBusiness  Is  Impossible 

The  only  thing  bigger  than  the  opportunity  that 


enabled,  secu¬ 
rity  has  taken  a  back  seat.  IT  managers  « 
often  give  themselves  a  false  sense  of 
security  with  a  standalone  or  partial  security 
solution.  They  forget  that  security  is  only 
as  strong  as  its  weakest  link  and  that 
eCompanies  need  an  integrated  and  com¬ 
prehensive  security  solution  that  provides  1 
best-of-breed  functionality. 


( Computer ® 
Associates 

Software  superior  by  design. 


©  2000  Computer  Associates  International,  Inc.,  Islandia,  NY  11749.  All  company,  product,  or  service  names  referenced  herein  may  be  trademarks  or 
sen/ice  marks  of  their  respective  owners.  'According  to  “Internet  Security  Software:  1999  Worldwide  Markets  &  Trends,”  by  IDC. 


Security,  Only 

ct  You  Like  This. 


eTrust  includes  a  comprehensive  set  of 
security  solutions  that  enable  eBusiness  by  f 
protecting  current  investments  and  allowing  \ 
customers  to  confidently  leverage  new 
technologies.  eTrust  offerings  enhance 
return  on  opportunity  for  any  eBusiness 
through  security  solutions  including  risk 
assessment,  attack  detection,  loss  preven¬ 
tion  and  powerful  management  -  all  critical 
components  of  a  comprehensive  security 
solution  for  a  successful  eBusiness. 


eTrust  Enables  eBusiness 

Trust  provides  all  the  security  solutions  an 
Business  needs: 

OMPREHENSIVE  —  eTrust  covers  all  secu- 
ty  functionality,  from  the  browser  to  the 
lainframe,  ensuring  complete  security  in 
)day’s  highly  complex  environments. 

EST-OF-BREED  —  eTrust  solutions  offer 
est-of-breed  functionality  across  the  board. 

\ITEGRATED  —  all  eTrust  solutions  are 
esigned  and  built  to  work  together  seam- 
>ssly  and  deliver  the  highest  level  of 
itegration. 

ASY  —  eTrust  solutions  are  easy  to  use, 
eploy,  and  administer,  ensuring  any  environ¬ 


ment  is  secured  quickly  and  correctly.  Your 
training  costs  will  go  down  as  your  security 
goes  up. 

MISSION-CRITICAL  —  eTrust  solutions  offer 
the  scalability,  depth,  and  robustness  fast¬ 
growing  and  successful  eBusinesses  need. 

eTrust  Is  Open  And  Extensible 

eTrust  allows  you  to  leverage  existing  invest¬ 
ments  in  security  solutions  —  you  will  never 
have  to  start  over  or  convert  anything.  And 
eTrust  can  be  implemented  one  function  at  a 
time  or  all  at  once  —  it’s  your  choice. 

And  since  eTrust  is  built  on  the  Unicenter 
TNG®  Framework™  it  lets  you  snap-in  other 
eBusiness  management  solutions  as  you  grow 
and  your  needs  change.  eTrust  is  built  on  a 
standards-based,  open  infrastructure,  so  it’s 
always  easy  to  plug  in  any  other  standards- 
compliant  products  or  solutions. 

eTrust  Is  Trustworthy 

eTrust  is  not  only  backed  by  the  world’s 
leading  security  software  company,*  it  is 
also  complemented  by  a  complete  set  of 
outcome-based  service  offerings,  including 
assessment,  implementation,  audit,  as  well 


as  complete  security  management  outsourc¬ 
ing.  CA  Services™  stands  ready  to  make  sure 
your  implementation  is  fast  and  trouble-free. 

If  your  company  is  making  the  difficult  transi¬ 
tion  to  an  eBusiness,  you  owe  it  to  yourself  to 
find  out  more  about  the  security  solution  more 
eBusinesses  trust. 

For  more  information, 
call  1-800-377-5327,  or  visit 

www.ca.com/solutions/enterprise/etrust/ 


eTrust 


TM 


Backed  By  The  #1  Security  Software  Company 


Assess 


Manage 


Protect 


Detect 


Enable 


■P  IT’S  BETTER  TO  HIRE  SOMEONE  WHO  CAN 
WRITE  A  PASSWORD-CRACKING  PROGRAM 

THAN  SOMEONE  WHO  KNOWS  ONLY 
HOW  TO  USE  IT,  ASSERTS  WELD  POND, 
RESEARCH  SCIENTIST  FOR  @STAKE. 


PHOTOS  BY  FURNALD/GRAY 


Cover  Story 


Security 


terns.  The  malicious  work  is  done  by  individuals  referred  to  as  crack¬ 
ers.  In  common  parlance,  the  two  types  are  known  as  white-hat  and 
black-hat  hackers.  Somewhere  in  the  middle  are  the  gray-hat  hackers, 
who  no  longer  actively  engage  in  malicious  hacks  but  maintain  their  ties 
to  the  underground  to  stay  abreast  of  new  exploits  and  techniques. 

Gray-hat  hackers,  like  those  found  in  LOpht  Heavy  Industries,  the 
recently  acquired  R&D  group  of  @Stake,  a  newly  formed  e-commerce 
security  company,  often  have  a  greater  level  of  experience  with  the 
tools  used  by  hackers.  “If  you’re  researching  vulnerabilities,  do  you 
want  to  hire  somebody  who  can  use  LockCrack  [a  password  crack¬ 
ing  program]  or  somebody  who  wrote  LockCrack?”  asks  Weld  Pond, 
a  research  scientist  with  Cambridge,  Mass.-based  @Stake. 

Obviously,  the  value  of  hiring  well-known  hacker  groups  like  LOpht 
is  that  you  know  what  you’re  getting.  Plenty  of  vandals  who  call  them¬ 
selves  hackers  can  break  into  systems  and  make  a  mess,  according  to 
Ken  Ammon,  founder  and  CEO  of  Herndon,  Va. -based  Network 
Securities  Technologies.  But  you  never  see  a  true  hacker’s  attack  com¬ 


SPACE  ROGUE,  a  research  scientist  for  £  Stake, 
goes  “underground"  to  get  information  to  help 
his  clients. 


ing,  and  it’s  often  impossible  to  even  detect  the  damage  he  has  done  or 
where  he  broke  in.  It’s  in  combating  that  kind  of  foe  that  attack  and 
penetration  skills  become  invaluable.  “If  you’re  never  going  to  hire  a 
hacker,  you’re  never  going  to  catch  a  hacker,”  says  Ammon. 

One  of  the  chief  benefits  of  working  with  some  breeds  of  hackers, 
like  the  gray-hats,  is  that  they  often  have  access  to  information 
about  known  security  holes  and  hacking  exploits  that  a  CIO,  or  a 
suit  in  hacker-speak,  could  never  get.  Through  chat  groups  and 
message  boards,  which  corporate  IT  staffers  generally  don’t  have 
the  time  or  the  inclination  to  visit,  hackers  discuss,  post  and 
exchange  information  about  security  problems.  When  a  company 
learns  about  a  vulnerability,  it  often  fixes  its  own  systems  but  buries 
any  information  about  the  problem  for  fear  it  might  become  pub¬ 
lic.  While  this  may  be  a  smart  move  from  a  public  relations  stand¬ 
point,  it  also  means  that  while  hackers  are  freely  exchanging  infor¬ 
mation  about  vulnerabilities  and  exploits,  companies  are  by  and 
large  kept  in  the  dark. 


www.cio.com 


JUNE  1,  2000  CIO  8  1 


Cover  Story  |  Security 

Space  Rogue  (like  other  hackers,  he  prefers  to  use  his  alias),  a 
research  scientist  for  @Stake  and  a  member  of  LOpht,  considers  his 
ties  to  the  underground  a  valuable  resource  for  the  companies  he  works 
with.  “The  underground  doesn’t  post  information  [for  companies  to 
see].  They  want  to  keep  it  to  themselves,”  he  points  out.  “By  having 
contacts  with  these  sorts  of  people,  we  get  hints  about  where  to  look  for 
holes,  we  find  them  and  publicize  the  problem.” 

Hackers  also  have  rather  traditional  methods  for  sharing  their 
information  through  vehicles  like  the  online  Hacker  News  Network 
Attrition.org,  where  a  page  called  “mirror”  reports  pages  of  corpo¬ 
rate  websites  that  have  been  hacked  and  defaced,  and  a  variety  of 
internet  relay  chat  sites.  CIOs  can  certainly  send  their  own  systems 
administrators  to  these  sites,  but  few  companies  have  the  resources 
to  dedicate  to  the  cause,  and  there  is  also  a  danger  to  having  corporate 
employees  surfing  these  pages  freely.  Many  times,  for  example,  hack¬ 
ers  set  up  the  sites  with  sniffers  (a  program  that  monitors  IP  packets 
traversing  a  local  network),  and  if  one 
of  your  employees  is  searching  for 
information  on  Windows  NT  vulner¬ 
abilities,  well,  there’s  got  to  be  a  rea¬ 
son.  A  hacker  is  now  armed  with 
some  very  valuable  information  about 
where  your  systems  may  be  weak. 

A  CIO  should  be  aware  that 
although  penetration  testing  can  pro¬ 
vide  enormous  value,  it  has  limits. 

“Breaking  in  is  easy,”  says  Fred  J. 

Rica,  a  partner  and  national  threat  and  vulnerability  assessment  leader 
with  PricewaterhouseCoopers’  technology  risk  services  division  in 
Morristown,  N.J.  “I  can  teach  anyone  to  be  a  hacker.”  But  that  alone 
doesn’t  help  the  company  strengthen  security.  There  has  to  be  a  cer¬ 
tain  level  of  business  knowledge  and  understanding  involved  in  order 
to  not  only  fix  the  problems,  but  also  create  a  security  policy  that 
will  prevent  recurrence.  According  to  Rica,  that  may  not  be  the  aver¬ 
age  hacker’s  strong  suit.  CIOs  should  also  understand  that  a  penetra¬ 
tion  test  is  just  a  snapshot  of  the  network  at  that  point  in  time.  The 
holes  that  are  there  today  can  be  fixed,  but  new  ones  can  be  created 
every  time  something  is  changed  on  the  network. 

Penetration  testing  should  be  viewed  as  an  occasional  test  for  the 
strength  of  its  defenses  rather  than  the  vulnerability  of  its  weaknesses, 
says  A1  Decker,  director  of  security  and  privacy  services  for  IBM  Global 
Services  in  Cary,  N.C.  Rather  than  throwing  a  brick  right  through  the 
window,  Decker  suggests  that  companies  check  for  the  network  equiv¬ 
alent  of  safety  glass.  If  there’s  a  screen  in  place,  safety  glass  in  the  win¬ 
dows  and  a  fence  outside,  “then  I’ll  throw  that  brick,”  he  adds. 

HOWTOPROTECTYOURCOMPANY 

Once  a  company  is  sold  on  the  value  of  hiring  a  hacker,  it  has  to 
know  how  to  mitigate  the  potential  security  risk  of  doing  so — steps 
that  CIOs  should  consider  whether  they’re  hiring  a  hacker  or  a  new 


systems  administrator.  Whether  the  hacker  works  directly  for  the 
company  or  through  a  third-party  vendor,  CIOs  need  to  conduct  a 
thorough  background  check  on  each  individual  being  considered.  For 
a  hacker  hire,  however,  the  check  takes  on  a  bit  more  significance 
because  any  criminal  history  where  computers  were  involved  should 
be  an  automatic  red  flag.  Some,  like  ex-convict  and  hacker  poster 
boy  Mitnick,  argue  that  because  some  computer  crimes  are  commit¬ 
ted  out  of  intellectual  curiosity  rather  than  the  desire  for  personal 
gain,  those  crimes  should  not  preclude  hackers  from  working  as  IT 
security  professionals.  But  CIOs  should  weigh  that  risk  carefully. 

Companies  should  also  check  references.  It’s  important  to  look 
carefully  at  the  resumes  of  all  who  will  be  working  on  their  systems 
and  ask  if  those  individuals  are  employees  of  the  company  or  subcon¬ 
tractors.  Even  if  the  individuals  are  part  of  a  security  vendor’s  on-staff 
team,  don’t  presume  that  the  background  work  has  already  been  done. 

Since  hackers  tend  to  develop  a  deep  expertise  in  one  or  two  par¬ 


ONEOF  THE  CHIEF  BENEFITS  OF 

WORKING  WITH  SOME  BREEDS  OF  HACKERS 
IS  THAT  THEY  OFTEN  HAVE  ACCESS  TO  INFORMATION 

ABOUT  KNOWN  SECURITY  HOLES  AND  HACKING 
EXPLOITS  THAT  A  CIO  COULD  NEVER  GET. 


ticular  areas,  certification  can  also  provide  some  insight  into  the  level  of 
experience  of  prospective  penetration  testers.  Most  hackers  doing  it  for 
illegal  purposes  wouldn’t  bother  to  put  the  time  and  effort  into  get¬ 
ting  certified,  so  if  the  individual  you’re  considering  is  a  certified  infor¬ 
mation  system  security  professional  or  a  systems  network  adminis¬ 
trator  professional,  chances  are  good  that  person  has  the  necessary 
skills  and  takes  his  work  seriously.  In  addition,  if  you  are  working  with 
a  security  vendor,  require  that  it  has  both  business  insurance  as  well 
as  key  personnel  clauses  in  the  contract  that  will  prevent  companies 
from  sending  people  other  than  those  who  were  originally  proposed  to 
conduct  the  work.  Such  steps  are  important  in  establishing  the  relia¬ 
bility  of  the  service  provider. 

Unfortunately,  none  of  this  information  will  tell  you  much  about  the 
ethics  of  the  person  in  question.  Rica  of  PricewaterhouseCoopers 
recounts  the  story  of  a  client  PWC  snapped  up.  This  client  was  on 
the  rebound  from  a  bad  experience  with  a  hacker  who  was  provid¬ 
ing  penetration  testing  services.  The  company  brought  in  the  hacker 
to  do  some  work,  and  the  very  next  month  2600:  The  Hacker 
Quarterly  featured  a  cover  story  on  how  to  hack  into  this  particular 
company.  Although  the  CIO  couldn’t  prove  a  direct  link,  he  decided 
that  the  two  events  were  far  too  coincidental  and  fired  the  individual. 

To  prevent  reading  about  your  company’s  system  secrets  in  the 
next  issue  of  a  hacker  magazine,  get  a  feel  for  the  morals  and  inten- 


8  2 


CIO  JUNE  1,  2000 


www.cio.com 


<! 


It  began  with  simple,  online  brochureware  and 
;ervers.  Next  came  stand-alone  Web  applications  and  application 
s.  Now,  e-business  demands  a  new  level  of  intelligence  for  your 
ny  to  compete:  The  Internet  must  be  used  to  improve  your  mission- 
l  business  processes.  That  means  you  need  to  bridge  the  Internet  world 
rour  corporate  data.  Introducing  ,  the 

hase  of  Internet  infrastructure.  And  it's  brought  to  you  by  Cerebellum™. 


We're  the  Brains  Behind  Your  e-Business 


THE  INTERNET  IS  EVOLVING 


For  more  information  on  Cerebellum's  Internet  data 
integration  capabilities  for  customers,  partners  and 
resellers,  please  contact  us  at  888.862.9898,  email 
smart@cerebellumsoft.com  or  visit  us  on  the  web. 


INTERNET  DATA  INTEGRATION 


Cover  Story  Security 

tions  of  the  person  by  meeting  with  him  face-to-face.  Brian  Martin, 
a  26-year-old  ex-hacker  and  security  consultant,  advises  CIOs  to  get 
to  know  these  people  personally  and  not  rely  on  a  piece  of  paper.  “No 
matter  what  the  resume  says,  15  minutes  in  a  bar  sipping  beers  and 
talking  to  them  will  tell  you  more  about  their  background  and 
ethics.”  Bringing  penetration  testers  into  the  office  for  at  least  the 
initial  portion  of  the  engagement  also  provides  the  added  bonus  of 
creating  an  opportunity7  for  the  company’s  security  personnel  to  learn 
from  the  penetration  testers.  When  Ernst  &  Young’s  penetration 
testing  team  starts  a  new  project  with  a  client,  for  example,  a  staff 
member  from  the  IT  department  they  are  working  with  sits  in  on 
the  work  they  are  performing.  This  creates  an  additional  level  of 
trust  and  an  atmosphere  of  mutual  education. 

GROWYOUROWNHACKERS 

Many  companies  simply  can’t  afford  to  risk  their  reputations  by  hir¬ 
ing  gray-  or  black-hat  hackers.  So  for  them,  developing  hacking  skills 
among  the  existing  members  of  their  IT  staff  is  a  very  appealing 
option.  Ernst  &  Young’s  Global  Security  Solutions  center  runs  a  one- 
week  “extreme  hacking”  course  out  of  its  Kansas  City,  Mo.,  head¬ 
quarters  and  in  cities  around  the  United  States  where  its  on-staff  secu¬ 
rity  experts  will  teach  IT  staff  members  the  ins  and  outs  of  hacking. 

The  course  offers  segments  on  internet  profiling  (gathering  infor¬ 
mation  about  a  company’s  internet  footprint),  hacking  Unix  and 
NT,  as  well  as  more  advanced  techniques.  It  then  follows  up  with  labs 
where  the  students  can  work  in  groups,  as  many  real-life  hackers 
do,  to  actually  hack  a  box  that  has  been  set  up  for  them  on  a  closed 
network.  Ricky  Soler,  an  information  security  analyst  with  Fiduciary 
Trust  in  New  York  City,  attended  one  of  the  recent  courses  because 
his  company  is  moving  into  e-commerce  and  wants  to  ensure  that 
its  systems  can’t  be  easily  hacked.  Soler,  like  most  of  the  students, 
was  surprised  by  how  easy  hacking  actually  is.  “The  first  couple 
[NT  and  Unix]  were  particularly  easy;  we  were  able  to  hijack  the 
password,  run  the  cracker  and  we  were  in.” 

Many  of  the  instructors  come  from  three-letter  government  agen¬ 
cies  such  as  the  CIA,  the  FBI  and  the  NSA.  Ron  Nguyen  came  from 
San  Antonio’s  Air  Force  Information  Warfare  Center,  where  he 
studied  the  attack  and  penetration  techniques  used  by  hackers  and 
developed  customer  countermeasures  to  detect  and  thwart  their 
preferred  methods  of  attack.  The  difference  between  the  Air  Force 
and  corporate  America  is  not  that  great  either.  Most  security  vul¬ 
nerabilities  in  both  areas  are  still  caused  by  simple  configuration 
errors,  outdated  firewall  access  control  lists  or  a  user’s  easily  guessed 
password.  In  addition  to  teaching  his  students  all  about  hacking, 
Nguyen  makes  a  point  to  reinforce  the  basics  of  good  information 
security  practices. 

As  for  corporate  security  professionals  like  Soler,  one  of  the  biggest 
benefits  of  attending  the  course — aside  from  the  knowledge  gained — 
is  the  relationships  it  created.  One  of  the  key  points  pushed  by  the 
extreme  hacking  instructors  is  the  importance  of  networking  with 


casMaracters 

Who's  who  in  the  world  of  hackers,  according  to  the 
online  hacker  Jargon  File 

Cracker:  A  malicious  meddler  who  tries  to  discover 
sensitive  information  by  breaking  into  computer  systems. 
Cracking  usually  involves  the  dogged  repetition  of  well- 
known  tricks  that  exploit  common  weaknesses  in  the 
security  of  target  systems. 

Hacker:  A  person  who  enjoys  exploring  the  details  of  pro¬ 
grammable  systems  and  how  to  stretch  their  capabilities. 
Hackers  also  relish  the  intellectual  challenge  of  creatively 
overcoming  or  circumventing  limitations. 

Phreaker:  One  who  practices  the  art  and  science  of  crack¬ 
ing  the  phone  network  (for  example,  to  make  free  long¬ 
distance  calls). 

Samurai:  A  hacker  who  is  hired  for  legal  cracking  jobs, 
snooping  for  factions  in  corporate  political  fights,  lawyers 
pursuing  privacy  rights  and  First  Amendment  cases,  and 
other  parties  with  legitimate  reasons  to  need  an  electronic 
locksmith. 

Script  Kiddies:  The  lowest  form  of  cracker,  script  kiddies 
do  mischief  with  scripts  and  programs  written  by  others, 
often  without  understanding  the  exploit. 

Sneaker:  An  individual  hired  to  break  into  places  to  test 
their  security. 

Reprinted  with  permission  of  Jargon  File,  version  4.1.0 

fellow  students.  In  the  future,  when  Soler  runs  up  against  a  security 
problem  or  questions,  he’ll  be  able  to  call  his  fellow  classmates  to 
talk  about  how  they  may  have  dealt  with  the  same  issue. 

Regardless  of  whether  you  choose  to  hire  penetration  testers  or 
not,  hackers  need  to  be  taken  seriously.  Michael  L.  Puldy,  who  heads 
IBM’s  Emergency  Response  Service,  points  to  events  like  Defcon, 
the  annual  gathering  of  serious  computer  hackers,  enthusiasts  and 
undercover  feds  as  evidence  that  hackers  are  going  somewhat  main¬ 
stream.  “There  are  people  from  the  FBI  and  the  State  Department 
there  because  they  want  to  hear  what  the  philosophies  are,”  says 
Puldy.  Companies  can  also  learn  a  great  deal  by  boning  up  on  the 
methods  and  exploits  of  the  hacker  community;  they  just  need  to 
give  careful  consideration  to  how  they  go  about  it.  QQ 


Daintry  Duffy,  senior  writer  and  fledgling  hacker,  goes  by  the  screen  name 
Coolio... whoops.. .Julio.  She  can  be  reached  at  dduffy@cio.com. 


8  4  CIO  JUNE  1.  2000 


www.cio.com 


It's  time  to  start  thinking  out  of  the  box 
when  it  comes  to  business  to  business. 


Dynamic  B2B.  The  power  to  work  with  anyone,  any  way  you  want.  Now  you  can  expand 
your  trading  network  to  include  all  partners,  from  small  to  large  to  eMarkets.  Then  maximize  those  part¬ 
nerships  by  integrating  them  into  your  enterprise  business  process  with  a  flexible,  XML-based  solution. 
The  future  of  eBusiness  is  Dynamic  B2B.  eXcelon  is  already  there.  **  a  ^ 

For  more  information,  visit  www.exceloncorp.com,  ^AtcLUl  I  corp. 


Enterprise  Systems 


As  ERP  implementations  falter  and 
fail,  many  people  think  the  answer 
is  more  training.  They're  wrong. 

ERpTraining 

StiNkS 

BY  MALCOLM  WHEATLEY 


Unless  you’ve  been  as  out-of-touch  as  the  Mars  Polar  Lander, 
you’re  doubtlessly  aware  that  the  ERP  industry  hasn’t  been 
performing  like  the  marvel  it  was  first  made  out  to  be. 

First  came  the  ERP  vendors’  pre-Y2K  plunging  sales  revenues  and 
falling  stock  values.  Second  came  the  realization  that  all  that  hard 

work  implementing  an  ERP  system  didn’t  actually 
guarantee  business  benefits — or  even  a  positive 
payback.  Take  Meta  Group’s  damning  finding,  for 
instance:  The  average  ERP  implementation  takes  23 
months,  has  a  total  cost  of  ownership  of  $15  million 


Reader  ROI 

►  Learn  how  training  differs 
from  education 


►  Find  out  why  it's  better  to 
keep  the  training  in-house 

►  Understand  why  CIOs  should 
be  cautious  of  industry 
average  training  budgets 


86  CIO  JUNE  1,  2000  •  www.cio.com 


Enterprise  Systems 


and  rewards  (so  to  speak)  the  business  with  an  average  negative  net  present  value  of 
$1.5  million.  And  the  news  gets  worse. 

An  alarmingly  long  list  of  top-drawer  integrators  have  fallen  flat  on  their  faces. 
Compared  to  these  disasters,  merely  spending  a  lot  of  money  on  an  ERP  implementa¬ 
tion  that  achieves  very  little  is  a  consummation  devoutly  to  be  wished. 

Hershey,  Pa. -based  Hershey  Foods,  for  example,  issued  two  profit  warnings  in  as 
many  months  in  the  run-up  to  last  Christmas.  Why?  Massive  distribution  problems  fol¬ 
lowing  a  flawed  implementation  of  SAP’s  R/3  ERP  system,  which  affected  shipments  to 
stores  in  the  peak  Halloween  and  pre-Christmas  sales  periods.  In  a  booming  stock  mar¬ 
ket,  Hershey  shares  ended  the  year  down  27  percent  from  its  year’s  high. 

And  Hershey  wasn’t  alone  in  its  misery.  In  November  1999, 
domestic  appliance  manufacturer  Whirlpool  of  Benton  Harbor, 

Mich.,  also  blamed  shipping  delays  on  difficulties  associated  with  its 
SAP  R/3  implementation.  Like  Hershey,  Whirlpool’s  share  price  dove 
south  on  the  news,  falling  from  well  over  $70  to  below  $60.  While 
these  two  have  (so  far)  been  the  highest-profile  implementation  deba¬ 
cles,  companies  as  diverse  as  Scottsdale,  Ariz.-based  trash  processor 
Allied  Waste  Industries;  Newark,  Del.-based  high-tech  fabric  maker 
W.L.  Gore  &  Associates;  and  industrial  supplies  distributor  W.W. 

Grainger  of  Lake  Forest,  Ill.,  have  all  reported  serious  difficulties. 

And  if  “serious  difficulties”  sounds  bad,  rest  assured  it  can  get 
much,  much  worse.  After  Carrollton,  Texas-based  pharmaceutical 
distributor  FoxMeyer  Drug  actually  collapsed  following  an  SAP  R/3 
implementation,  its  bankruptcy  trustees  filed  a  $500  million  lawsuit 
in  1998  against  the  German  ERP  giant,  and  another  $500  million  suit 
against  co-implementer  Andersen  Consulting.  (Both  cases  were  unre¬ 
solved  at  the  time  of  writing.) 

So  what’s  going  on?  The  good  news — if  that’s  the  right  word — is 
that  most  experts  agree  that  such  failures  are  not  systemic.  “Very 
rarely  are  there  instances  when  it’s  the  ERP  system  itself — the  actual 
software — that  fails,”  says  Jim  Shepherd,  senior  vice  president  of 
research  at  Boston-based  AMR  Research.  Public  pronouncements 
by  both  SAP  and  Hershey,  he  notes,  have  acknowledged  that  the 
software  does  what  it  is  supposed  to  and  that  no  big  fixes  or  patches 
are  planned.  What’s  more,  he  adds,  the  prudent  observer  will  differ¬ 
entiate  between  real  implementation  failures  and  not-so-real  fail¬ 
ures.  “Blaming  the  failure  on  a  system  implementation  has  become 
a  convenient  excuse  for  companies  that  have  missed  their  quarter- 
end  [earnings]  target.” 

As  for  blame,  it  is  evenly  spread.  SAP  implementations  are  no  more 
likely  to  go  down  the  tubes  than  ERP  systems  from  other  vendors: 

88  CIO  JUNE  1,  2000  •  www.cio.com 


W.L.  Gore’s  system,  for  example,  came  from  Pleasanton,  Calif.-based 
PeopleSoft.  “When  an  ERP  project  unravels,  or  is  seen  not  to  perform 
well,  one  of  the  suppliers  is  usually  chosen  as  the  culprit,”  says  David 
Duray,  London-based  global  partner  responsible  for  the  SAP  imple¬ 
mentation  business  at  PricewaterhouseCoopers.  “In  my  experience, 
this  is  usually  more  of  a  political  decision  than  a  proper  problem- 
source  identification  exercise — and  SAP,  over  the  last  few  years,  has 
been  a  popular  target.” 

Furthermore,  adds  Roger  Phillips,  an  IT  analyst  at  specialist  invest¬ 
ment  bank  Granville  in  London,  which  tracks  the  global  ERP  market, 


„  #h„  nought  you  BlackICE ",  continues 
network  ICE,  the  company  that  g  hackers  and  malicious  employees 

to  pioneer  enterprise-wide  protec  ion  Whether  your  notebooks,  desktops 

throughout  today’s  or  residing  on  a  partner’s  extranet,  Network  ICE 

~  • — — - 


sing  revolutionary  anti-hacker  technology,  Network  ICE  products  act  like  an 
Internet  bodyguard;  inspecting  every  packet,  blocking  those  that  are  hostile 
a  owing  harmless  data  to  pass,  yet  always  ready  to  step  in  and  intercept  an 
attack.  Even  from  someone  you  trust.  Network  ICE  products  complement 
existing  firewalls  and  VPNs.  Visit  www.networkice.com  to  learn  more 
about  our  enterprise  solutions,  and  how  to  stop  hackers  cold.. 


Network 

I  •  C  •  E 


www.  net  workice  .com 


Stop  Hackers  Cold 


©1998-2000  Network  ICE  Corporation.  All  nghts  reserved. 


Enterprise  Systems 


there  is  no  evidence  that  geography  is  a  significant  differentiator  in  the 
success  stakes.  Disasters,  he  believes,  “simply  go  with  the  ERP  terri¬ 
tory.”  There  are,  he  says,  “no  cultural  or  managerial  foibles  that  make 
American  ERP  implementations  any  more  predisposed  to  disasters 
than  any  other  country’s  implementations.” 

So  what  does  lie  behind  ERP  disasters?  And  behind  the  rather 
longer  list  of  costly-but-underwhelming  implementations  typified  by 
that  now-infamous  Meta  Group  report?  Increasingly,  experts  reckon 
that  they’ve  found  the  smoking  gun:  poor  training.  Not  the  techni¬ 
cal  training  of  the  core  team  of  people  who  are  installing  the  software, 
but  the  education  of  the  broad  user  community  of  managers  and 
employees  who  are  supposed  to  actually  run  the  business  with  it. 

So  Much  Training, 

So  Little  Benefit 

As  few  as  10  percent  to  15  percent  of  ERP  implementations 
have  a  smooth  introduction  that  delivers  the  anticipated  ben¬ 
efits,  says  A.  Blanton  Godfrey,  chairman  and  CEO  of  the 
Juran  Institute,  a  Wilton,  Conn. -based  consultancy.  The  remainder 
either  experience  teething  problems  or  a  significant  shortfall  in  deliv¬ 
ered  benefits — with  a  full  30  percent  of  companies  receiving  what 
he  calls  “a  nasty  surprise.”  It’s  not  a  disaster  of  Hershey  or  Whirlpool 
dimensions,  but  it’s  still  a  kick  in  the  teeth.  The  fascinating  variable 
to  look  at,  according  to  Godfrey,  is  what  characterizes  the  lucky 
10  percent  to  15  percent.  It’s  not  luck;  it’s  better  training. 

In  one  sense,  this  isn’t  new.  Everyone  knows  that  training  is  impor¬ 
tant.  Especially  the  ERP  software  vendors  themselves,  who  earn 
handy  revenues  from  design-once,  recycle-many-times  training 
courses.  And  most  especially  third-party  training  vendors,  the  bulk 
of  whose  livelihoods  come  from  running  courses  on  how  to  operate 
an  ERP  vendor’s  system.  And  just  look  at  the  mind-blowing  variety  of 
training  formats  available:  web-based  virtual  classrooms,  computer- 
based  training,  knowledge  warehouses,  video  courses,  self-study 
books,  pop-up  help  screens...  an  almost  endless  menu  to  suit  almost 
every  need  and  budget. 

The  provision  of  all  that  training,  points  out  Cushing  Anderson, 
a  senior  research  analyst  with  Framingham,  Mass.-based  IDC  (a  CIO 
sister  company),  has  become  a  giant  business  in  its  own  right. 
Revenues  for  web-based  ERP  training  in  the  United  States  alone  were 
$915  million  in  1998,  projected  to  grow  to  $2.8  billion  in  2003.  The 
logic  is  inexorable,  he  says:  “The  better  the  training,  the  faster  you’ll 
see  the  business  metrics  move  in  the  direction  you’re  looking  for.” 

But  the  consensus  that’s  emerging  is  that  the  training  that  matters 
isn’t  techy,  “this  field  shows  this;  this  button  does  that”  training.  In 
fact,  what  we  normally  call  training  is  increasingly  being  shown  to 
be  relatively  worthless.  What’s  called  for,  it  seems,  is  an  ability  to  fig¬ 
ure  out  the  underlying  flow  of  information  through  the  business  itself. 


The  traditional  view  of  training  may  blind  the  unwary  to  its  signifi¬ 
cance  and  to  the  tightly  woven  links  that  exist  between  training, 
change  management  and  staff  adequacy. 

The  Why  Versus  the  How 

he  first  problem  is  that  word:  training.  It  conjures  up  images 
of  dogs  jumping  through  hoops.  This  is  not  helpful. 

“I  separate  training  into  two  parts — education  and  training,” 
says  John  Conklin,  vice  president  and  CIO  of  World  Kitchen  (for¬ 
merly  Corning  Consumer  Products  Co.,  manufacturer  of  Pyrex  and 
Corningware)  of  Elmira,  N.Y.  “Education  is  all  the  why,  who  and 
where  issues,”  Conklin  says.  “Training  is  the  how  part  of  the  equa¬ 
tion.”  And  of  the  two,  he  says,  “education  is  the  bigger  piece  of  the 
puzzle.  If  people  don’t  go  through  this  education,  you  won’t  have 
their  hearts  and  you  won’t  have  their  minds.” 

There’s  a  tendency  for  companies  to  fall  into  the  trap  of  putting 
employees  through  training  programs  that  are  too  software-specific — 
an  easy  mistake  to  make,  but  one  that  ignores  the  fact  that  ERP  sys¬ 
tems  are  designed  to  operate  by  (literally)  codifying  a  set  of  business 
processes.  “No  matter  what  application  an  organization  is  imple¬ 
menting,  they  are  usually  better  at  the  keystroke  and  transaction 
training  than  they  are  at  the  business-and-people  processes  educa¬ 
tion,”  says  IDC’s  Anderson. 

And  providing  that  education  can  be  tricky.  When  St.  Louis-based 
Purina  Mills  implemented  SAP  R/3  in  its  55  plants,  the  commercial 
animal-feed  producer  outsourced  the  training  task  to  a  third  party, 
says  Operations  Control  Director  Steve  Hunt.  In-house  resource 
constraints  were  a  factor,  says  Hunt— the  company  wanted  its  best 


9  0  CIO  JUNE  1.  2000 


www.cio.com 


STONEBRIDGE 


•'  ’*s:‘‘'<.<,'rt?Jf?':' 


TECHNOLOGIES 


!#&&%$!& 


§ppp$»t 


II 


Optimism  soared  at  the  shareholders  meeting  as  I  outlined  our  e-services 

I 


strategy.  They  grilled  me  about  how  we'd  get  there  —  infrastructure,  information, 


interaction,  the  works.  Now  we've  got  to  deliver.  Fast." 


Rapid  deployment  keeps  your  e-readiness  initiatives  on  track.  Stonebridge 


■ 


to 


deliver  innovative  solutions  —  fast.  Learn  more.  Visit  Stonebridge,  a  certified 


Sun  reseller,  at  www.sbti.com/e-ready  or  call  800-776-9755. 


:■".  Xo^%}  -•• ; SsIbivAi !.<•''' »•**%&*>;?  ••~;!j,.  -■ . .' ». >j^^j2ii.‘£2iiSnBEii 


*§sS®@ 

LUE  ADDED  ^HMKMHHHH^H 

""  LER 

se 

CERTIFIED 


...  ..  ,.„J:  '  :'*•'.'-?£&'')■■■■  •  ..../;  •’  y  '*- 


Alabama,  Florida,  Georgia,  North  Carolina,  Oklahoma,  Tennessee,  Texas 


Enterprise  Systems 


“We  made  the  mistake  of  teaching  everybody  how  to  do 
their  job  but  nothing  else....  They  didn’t  understand  the 
ERP  process,  the  degree  of  integration  and  the  importance 
of  data  being  right." 

-Keith  Bearden,  director  of  IS  and  CIO,  A-dec 


people  implementing,  not  training.  But  also,  he  says,  “We  assumed 
that  a  third  party  training  partner  would  add  valuable  insight  into 
training  techniques  that  had  already  been  proven  in  their  previous 
implementations.  ” 

The  result  was  an  awkward  first  day,  which,  Hunt  recalls,  “saw 
end  users  at  the  very  first  break  on  the  very  first  day  of  training  stating 
that  they  were  going  home  unless  someone  came  into  the  classroom 
to  help  them  translate  the  material.”  The  problem?  “A  complete 
system  change  is  like  learning  a  language,”  explains  Hunt.  “In  the 
beginning,  you  need  to  translate  the  new  language  into  the  old  in 
order  to  understand  the  meaning.  In  this  case,  our  trainers  couldn’t 
provide  that  translation,  as  they  didn’t  understand  our  processes — for 
example,  they  could  demonstrate  how  to  enter  a  goods  receipt,  but 
they  couldn’t  explain  when  you  should  do  it,  or  how  to  find  the  right 
purchase  order  to  apply  it  to.” 

In  the  end,  says  Hunt,  it  became  clear  that  the  training  company 
just  wasn’t  up  to  the  job.  “We  asked  them  to  leave  at  the  end  of  the 
first  week.”  Rather  than  opt  for  another  third-party  provider,  Hunt 
and  his  team  spent  six  months  constructing  a  course  that  they  could 
deliver  themselves — and  did  so,  in  a  complete  reversal  of  the  origi¬ 
nal  strategy. 

What  Hunt  and  Purina  Mills  discovered  was  that  what  their  employ¬ 
ees  really  wanted  and  needed  to  learn  about  was  the  whys,  wheres 
and  whos  of  the  business  process  not  the  hows  of  the  ERP  system. 

“Companies  often  mistakenly  regard  SAP  implementation  as  a 
purely  technical  issue,”  affirms  Byron  Fiman,  principal  and  cofounder 
of  Implementation  Management  Associates,  a  Brighton,  Colo.-based 
change  management  consultancy.  “In  fact,  at  least  half  the  issues  in 
ERP  disasters  are  not  technical  but  people  related  and  culture 
related.”  In  terms  of  getting  things  right,  he  adds,  “the  soft  stuff  is 
really  the  hard  stuff.” 

And  even  if  a  Hershey-  or  Whirlpool-style  disaster  doesn’t  loom,  a 
failure  to  deliver  benefits  is  all  too  likely.  “The  screens  are  up,  but  noth¬ 
ing  has  changed:  the  cycle  times  are  the  same,  customer  satisfaction 
metrics  don’t  shift  and  the  costs  remain  the  same,”  Fiman  says.  The 
problem  is  that  too  many  companies  pay  lip  service  to  the  education 
part  of  the  pre-ERP  change  management  process.  “Every  SAP  imple¬ 
mentation  partner  says  that  training  is  important,  but  it’s  often  one 
of  the  first  things  to  go  when  the  talks  about  pricing  get  tough.” 

92  CIO  JUNE  1,  2000  •  www.cio.com 


Millions  for  Software, 

Pennies  for  Understanding 

tCrT-t  oo  many  companies  treat  training  as  a  check-the-box 
activity,”  says  Dan  Klein,  vice  president  of  education 
JL  services  at  PeopleSoft.  “The  resulting  mind-set:  ‘Did  you 
train  the  users?’  ‘Yup,  we  trained  the  users.’” 

Just  as  common,  training  typically  occurs  at  the  end  of  the  imple¬ 
mentation  cycle,  when  activities  are  often  running  late  and  being  com¬ 
pressed.  So  training,  too,  gets  squashed  in  as  a  last-minute  activity. 
“One  of  my  favorite  questions,”  Klein  says,  “when  speaking  at  user 
seminars  is  to  ask,  ‘How  many  people  would  go  about  their  train¬ 
ing  differently  on  their  next  implementation?’  Seventy-five  percent 
of  the  people  put  their  hands  up  and  say  that  next  time  they’d  allow 
more  time  for  it,  and  that  they’d  tailor  it  more  around  their  own 
business  processes.” 

A  typical  result  of  such  skimping,  says  David  Beresford,  executive 
director  of  one  of  Europe’s  premier  SAP  rescue  services,  systems 
implementation  consultancy  Diagonal,  of  Farnham,  England,  is  that 
users  often  fail  to  appreciate  the  consequences  of  their  actions — with 


e 

oblix 


Oblix  simplifies  the  e-business 
infrastructure  with  a  powerful, 
distributed  solution  for  managing 
user  profiles  and  policies. 


Patchil-t^ 

The  FT  Super  Sue 

Employs  directory-enabled  and 
browser-based  functionality  for 
administering  your  network, 
while  detecting  security  threats 
and  breaches. 


Comprehensive  remote  user 
management  and  ease  of  use  for 
large-scale  deployments  of  policy- 
enabled  virtual  private  networks. 


Business  Layers 

Directory-based  eProviuoning  Solutions 


Streamlines  and  automates 
the  provisioning  of  IT  resources 
and  services  across  extranets 
and  intranets,  based  on 
business  requirements. 


Novell  and  partners  put  the 
power  in  your  hands. 


Your  e-business  strategy  requires  solutions  that  work  well  with  the  Net's  directory 
Novell  c^°'ce — Novell®  NDS®  eDirectory".  And  only  solutions  with  the 

Directory-Enabled  mark  are  flight-tested  and  proven  for  simple 
integration  and  peerless  interoperability.  It's  the  simplest  way  to 
unite  systems,  data  and  applications  with  markets  in  the  new  Net 
economy.  So  enable  yourself  and  find  these  Directory-Enabled 
solutions  for  NDS  eDirectory  at:  http://developer.novell.com/enabled. 


DIRECTORY 

ENABLED 


©  2000  Novell,  Inc  Novell  and  NDS  are  registered  trademarks,  and  eDirectory  is  a  trademark  of  Novell  in  the  U.S  and  other  countries.  All  other  products  and 
services  mentioned  are  property  of  their  respective  owners. 


Novell. 


Enterprise  Systems 


disastrous  results.  Informal  practices  that  worked  just  fine  in  the  era 
of  paper  procedures  or  standalone  legacy  systems  can  have  cata¬ 
strophic  effects  on  an  integrated  ERP  environment. 

“The  classic  example  is  the  sales  order  process,”  says  Beresford. 
“In  the  past,  people  could  put  in  the  wrong  price,  the  wrong  cus¬ 
tomer.  the  wrong  delivery  point — and  somehow,  the  business  coped. 
Now,  surprise,  surprise,  they  don’t  get  their  invoice  paid.  And  it’s  even 
worse  if  the  wrong  product  is  entered.  What  people  need  to  under¬ 
stand  is  that  the  sales  orders  are  now  automatically  linked  to  the  man¬ 
ufacturing  and  accounting  functions." 

They  didn’t  understand  this  at  A-dec,  a  privately  held  dental  equip¬ 
ment  manufacturer  headquartered  in  Newberg,  Ore.,  which  went  live 
with  a  Baan  system  in  1997.  “We  made  the  mistake  of  teaching  even  - 
body  how  to  do  their  job  but  nothing  else,”  says  Director  of  IS  and 
CIO  Keith  Bearden.  “Every  body  knew  the  keystrokes  to  do  their 
job,  but  that  was  all.  They  didn’t  understand  the  ERP  process,  the 
degree  of  integration  and  the  importance  of  data  being  right.  A  clerk 
would  enter  an  order  incorrectly  and  manufacturing  would  start 
making  it.  Changes  to  sales  orders  after  we’d  started  manufacturing 
were  a  real  problem.” 

Six  months  later  Bearden  threw  in  the  towel  and  conceded  that 
users  needed  better  training.  But  how?  Baan  ran  a  course,  but  it  lasted 
a  week,  cost  S5,000  per  head  and,  Bearden  decided,  wasn't  about 
A-dec ’s  business  processes.  So  the  company  decided  to  develop  a 
course  itself,  using  instructing  staff  from  Portland  State  University’s 
business  school.  “Folks  from  the  university  came  to  the  business, 
talked  to  people  about  how  we  operated  and  worked  with  a  team 
from  inside  A-dec  to  develop  the  course  and  then  give  it,”  says 
Bearden.  In  all,  some  450  employees  went  through  the  one-day 
course  during  the  summer  and  early  fall  of  1998. 

“The  human-factor  side  of  ERP — understanding  the  relationship 


9  4  CIO  JUNE  1.  2000  •  www.cio.com 


between  the  people  in  receiving,  shipping,  manufacturing  and  the  cus¬ 
tomer — is  crucially  important,”  adds  Johnnie  Foster,  vice  president 
and  CIO  of  St.  Louis-based  specialty  chemical  manufacturer  Solutia. 
The  timetable  for  Solutia’s  own  SAP  R/3  implementation,  which 
concluded  in  May  1999,  he  adds,  was  driven  both  by  the  need  to 
achieve  Y2K  compliance  as  well  as  separate  from  former  parent 
Monsanto.  “Now  we’re  going  back,  taking  it  to  another  level  and 
getting  people  to  better  understand  their  role  in  the  process:  This  is 
what  you’re  doing,  this  is  why  you’re  doing  it  and  here’s  how  it 
impacts  other  people,”  he  says. 


The  Black  Hole  of  Middle 
Management 

Without  understanding  the  whys  of  the  process,  decisions 
that  would  make  sense  in  a  pre-ERP  environment  quickly 
turn  sour — particularly  when  those  decisions  are  made 
by  middle  managers  whose  day-to-day  tasks  revolve  not  around  the 
computer  screen  but  the  directing  of  people  who  sit  at  the  computer 
“We  call  it  the  black  hole  of  middle  management,”  says 
Implementation  Management  Associates’  Fiman.  The  problem  that 
he  identifies  is  one  of  cultural  inertia.  “Companies  have  confused 
culture  with  wallet  cards,”  he  says,  referring  to  the  printed  crib  sheets 
on  which  businesses  set  out  their  value  statements  and  mission  state¬ 
ments  in  a  handy-but-forgettable  format.The  result?  Managers  who 
talk  the  talk  but  walk  any  which  way  they  choose. 

Consequendy,  when  companies  hit  Hershey-snie  problems,  there’s 
an  instinctive  middle  management  reaction  to  ship  products  to  cus¬ 
tomers  rather  than  lose  sales  even  if  that  means  circumventing  the  sys- 


NEFAB  North  America,  Midwest  “Go  Live”  with  Intentia 


Schaumburg,  IL  -  NEFAB  North  America,  Midwest  Division  recently  celebrated  a  successful  implementation  of  the 
Enterprise  Application  Solution,  Movex.  Richard  Steele,  Controller  of  NEFAB  North  America,  Midwest  accepted  the 
“Go  Live”  award  on  behalf  of  the  implementation  team. 


NEFAB  North  America,  Midwest  is  the  U.S. 
division  of  Sweden’s  NEFAB  AB,  a  global  leader  in  the  production  of  customized 
packaging  solutions  for  secure  shipping  of  transport-sensitive  goods,  such  as 
electrical  and  electronic  components  and  equipment,  automotive  parts,  heavy 
machinery,  and  recreational  vehicles. 


“Since  going  live  in  the  U.S.,  our  lead  time  has  been  cut  by  a  week  and  we  have 
been  able  to  reduce  our  materials  inventory  by  20  to  25  percent”  said  Richard 
Steele.  Steele  adds  that  the  Company  is  well  positioned  for  e-business  initiatives. 
“The  ability  to  configure  and  enter  customized  product  orders  on-line  opens  the 
door  to  faster  order  processing  and 
transaction  cycles.  This  will  enable  NEFAB 
to  sell  direct  to  customers  as  well  as 
third-party  logistics  providers.” 


To  experience  a  “Go  Live”  celebration  with  Intentia,  call  us  at  800.SW.MOVEX,  Extension  51784. 


1700  East  Golf  Road,  Suite  900  Schaumburg,  IL  60173  800.SW.MOVEX  Fax:  847.762.0901  www.intentia.com 


O  fnt-entfa 


A 


Enterprise  Systems 


“Senior  managers  often  don’t  particularly  want  to  be  told  that 
there's  a  high  level  of  risk  and  that  there’s  a  great  deal  of 
expenditure  involved  in  minimizing  it.” 

-Jim  Shepherd,  senior  vice  president  of  research,  AMR  Research 


tern,  says  David  Dobrin,  chief  business  architect  at  Benchmarking 
Partners  in  Cambridge,  Mass.  And,  says  Dobrin,  that’s  just  about 
the  worst  thing  you  can  do.  Not  only  does  the  order  still  sit  in  the 
system,  ostensibly  unfulfilled,  but  the  actual  inventory  is  now  out  of 
whack  with  the  inventory  logged  in  the  system.  And  without  the 
shipment  going  through  the  system,  it’s  hard  to  raise  an  invoice. 
“The  ship-it-anyway  syndrome  is  definitely  a  lack  of  understand¬ 
ing,”  slams  Dobrin.  “People  need  to  know  what  an  incredibly  stupid 
idea  that  is.” 

Training  in  how  to  operate  the  system  will  not,  however,  help  the 
middle  manager  see  down  the  road  far  enough  to  decide  to  forgo 
the  short-term  benefit  of  shipping  product  come  what  may.  Only  a 
broader-based,  holistic  education  in  the  company’s  ERP-mediated 
business  processes  will  do  that. 

But  if  end-user  and  middle-management  training  is  so  important, 
why  isn’t  it  given  more  priority?  One  answer,  perversely,  is  that  it  is 
being  given  more  priority — now.  “Companies  have  begun  to  wake  up 
to  the  fact  that  training  is  a  key  requirement,”  says  Patrick  Newton, 
former  CEO  and  president  of  third-party  training  company  DA 
Consulting  Group  of  Houston.  Training  as  a  proportion  of  overall 
budgeted  project  costs  was  typically  around  5  percent  as  recently  as 
two  years  ago,  he  notes,  citing  analysts’  published  estimates.  Now, 
he  says,  the  figure  has  more  than  doubled,  to  around  1 1  percent  of 
project  budget. 

While  that  is  reassuring  news,  the  analysts  are  less  sanguine.  “Very 
wide  ranges  make  industry  averages  meaningless,”  observes  Debra 
Hofman,  managing  director  of  Benchmarking  Partners,  whose  own 
study  found  that  even  though  training  averaged  8  percent  of  total  proj¬ 
ect  cost,  the  actual  costs  of  training  ranged  anywhere  from  1  per¬ 
cent  to  30  percent.  CIOs  who  aim  for  the  average  figure  (and  nearly 
every  CIO  interviewed  for  this  story  could  instantly  cite  what  per¬ 
centage  of  their  company’s  implementation  costs  were  dedicated  to 
training)  may  therefore  be  running  the  risk  of  undershooting  the 
target  requirement. 

Senior  Doesn’t  Mean  Smarter 

nd  therein  lies  another  problem.  ERP  training  needs  to 
embrace  senior  management — and  early  on  in  the  process, 
when  budgets  and  timescales  are  still  fluid,  argues  AMR 
Research’s  Shepherd.  “Senior  managers  often  don’t  particularly  want 


\S  ^°r 

r\Gh$ 


to  be  told  that  there’s  a  high  level  of  risk  and  that  there’s  a  great  deal 
of  expenditure  involved  in  minimizing  it,”  he  maintains.  “It’s  just 
not  a  message  they  want  to  hear.”  The  result  is  an  invidious  con¬ 
spiracy  of  silence.  “The  people  with  the  message  don’t  want  to  tell 
it,  and  the  people  to  whom  it  should  be  told  don’t  want  to  hear  it.” 

In  particular,  he  worries,  the  senior  and  middle  management  of 
American  companies  don’t  have  the  extensive  operating  background 
of,  say,  their  German  counterparts.  “Unlike  in  German  companies, 
where  managers  have  engineering  degrees  and  shop  floor  experi¬ 
ence,  too  many  American  managers  have  management  degrees  and 
have  come  from  business  school  straight  into  a  management  role,” 
says  Sheperd. 

The  result?  A  critical  blind  spot  when  it  comes  to  understanding 
how  their  brand-new  systems  actually  operate  in  the  lives  of  their 
employees  and  on  the  shop  floor.  But  with  awful  examples  like 
Hershey  and  Whirlpool  to  focus  their  thoughts,  companies  may  be 
expected  to  give  some  hard  thought  to  eliminating  that  blind  spot. 

It’s  either  that,  or  that  light  you  see  at  the  end  of  the  implementa¬ 
tion  tunnel  will  probably  turn  out  to  be  that  of  an  oncoming  train. 
And  you  know  how  that  story  ends.  BE] 


Do  you  think  ERP  training  stinks?  Give  us  an  earful  at  letters@cio.com. 
Malcolm  Wheatley  can  be  reached  at  malcolmwheatley@compuserve.com. 


96  CIO  JUNE  1,  2000  •  www.cio.com 


AJILON. 

INFORMATION  TECHNOLOGY  SERVICES 

www.ajilon.com 


I 


T 


T 


T 


r  T" 

systems  transformation  functional  outsourcing  systems  security  systems  managed  maintenance  e-commerce  software  testing  supplemental  staffing 


I  have  to  make  sure  that  everyone 
understands  we  have  little  control 
over  the  stock  price  on  a  daily  basis.” 

-Phillip  Merrick,  webMethods 


9  8  CIO  JUNE  1,  2000 


www.cio.com 


Web  Business 


1 

. 

I 


Is  the  grass  really  greener  on  the  other  side  of  the  IPO ? 

SURVIVED 

These  three  companies  are  finding  out. 

MY  IPO 

BY  BETH  STACKPOLE 


There  are  thousands  of  internet  entrepreneurs  who  would  like  to  be  wearing 
Phillip  Merrick’s  shoes.  Merrick’s  company,  webMethods,  which  makes 
software  that  facilitates  business-to-business  e-commerce,  launched  its  initial 
public  offering  on  Feb.  11,  going  out  at  $35  a  share.  Weeks  later,  the  Fairfax, 
Va. -based  company’s  stock  price  shot  up  to  over 
$300,  and  the  company,  which  had  revenues  of  $15 
million  in  1999,  at  one  point  had  a  market  capital¬ 
ization  somewhere  in  the  $9  billion  range.  In  March 
its  stock  price  was  trading  in  the  low  $230s. 


Reader  ROI 

Learn  the  challenges  startups 
face  when  they  go  public 

Find  out  why  Wall  Street  wants 
to  dictate  technology  needs 

Read  how  newly  public  compa¬ 
nies  keep  momentum  going 


www.cio.com 


JUNE  1,  2000  CIO  9  9 


Web  Business 


“What  we’re  finding  is  a  double-edged  sword— with  the  stock 
low,  there’s  tremendous  room  for  growth,  but  it’s  easy 
for  other  companies  to  pick  off  employees  because  there’s 
not  a  lot  holding  people  here  other  than  their  job  and 
wanting  to  work  in  a  particular  segment  of  the  industry.” 

-Greg  Sutyak,  CFO,  Audiohighway 


The  price  has  since  fallen,  along  with  the 
price  of  just  about  everything  Nasdaq- 
related,  but  webMethods  still  represents  a 
financial  triumph — at  least  until  Wall  Street 
takes  another  tumble. 

So  how  did  President  and  CEO 
Merrick  and  his  275  employees,  all 
paper-based  millionaires  post-IPO,  cel¬ 
ebrate?  The  heady  festivities  included 
clearing  out  cubes  at  the  company’s 
new  headquarters  to  host  a  modest, 
catered  party  for  employees  and  their 
families  as  well  as  Merrick  springing 
for  vanity  plates  bearing  the  com¬ 
pany’s  stock  symbol,  WEBM,  for  his 
5-year-old  Honda  Accord. 

Hang  on  a  dotcom  second.  If  you  believe 
all  the  hype,  this  kind  of  moderation  isn’t  part 
of  the  post-IPO  era.  Among  other  benefits,  a 
high-flying  IPO  is  supposed  to  yield  instant 
wealth,  showering  everyone  from  top-ranked 
management  to  the  lowest-level  employee 
with  enough  options  to  buy  new  vacation 
homes  or  fancy  cars,  and  maybe  even  allow 
them  to  retire  early  or  fund  their  own  internet 
startup.  The  American  dream  of  the  digital 
age  may  be  coming  true  for  a  growing  num¬ 
ber  of  high-tech  workers,  but  the  truth  is  that 
most  post-IPO  companies,  even  the  stars  like 
webMethods,  are  far  from  a  cushy  sanctum 
for  the  rich  and  famous.  Rather,  with  the 
added  scrutiny  of  Wall  Street  and  investors  on 
financial  performance  each  quarter,  post-IPO 
life  is  often  the  same  frenetic,  nose-to-the- 


grindstone  environment  that  it  was  before 
going  public.  And  post-IPO,  there’s  more 
pressure  than  ever  on  top  management — 
from  the  CEO  to  the  CIO — to  foster  a  culture 
that  keeps  employees  focused  on  the  com- 


WEBM 


pany’s  long-term  strategic  goals  and  vision 
instead  of  the  short-term  impact  of  stock 
price  fluctuations  on  individual  portfolios. 
“The  tone  has  to  be  set  by  the  executive  staff 
that  this  isn’t  important — that  you’re  work¬ 
ing  as  hard  as  you  were  before,  if  not  harder,” 
notes  Ted  Schlein,  a  general  partner  at 
Kleiner,  Perkins,  Caufield  &c  Byers,  a  venture 
capital  firm  in  Menlo  Park,  Calif.,  that  has 
recently  funded  such  dotcom  players  as  used- 
car  marketplace  AutoTrader.com  and  the 
web  search  tool  Google.  “People  think  of  the 
IPO  as  glamorous,  but  more  than  anything 
it’s  a  milestone — a  marketing  event  in  today’s 
world.  It’s  up  to  the  executive  team  to  mini¬ 
mize  its  impact  on  how  the  company  oper¬ 
ates  on  a  daily  basis.” 

WebMethods’  Merrick  is  all  too  aware  of 


that  responsibility.  That’s  why  he’s  made  it 
a  top  priority  among  his  executives,  includ¬ 
ing  his  technologists,  to  set  the  tone  for  mod¬ 
eration  and  prepare  employees  for  life  as  a 
public  company.  “I  have  to  make  sure  that 
everyone  understands  we  have  little 
control  over  the  stock  price  on  a  daily 
basis,  but  a  lot  of  control  over  the  long 
term,  and  that’s  completely  tied  up  in 
how  we  execute,”  says  Merrick. 
“After  the  IPO,  a  companywide  e-mail 
went  out  listing  the  top  IPOs  of  all 
time,  and  we  were  on  that  list.  But  as 
someone  pointed  out,  of  those  10 
companies,  eight  were  currently  trad¬ 
ing  below  their  first-day  closing  price.” 
The  message,  Merrick  says,  is  clear:  web¬ 
Methods  has  no  interest  in  becoming  part 
of  that  group. 

Only  time  will  tell  if  webMethods  will 
make  the  cut.  More  than  50  percent  of  tech¬ 
nology  companies  trade  below  their  IPO 
price  within  two  years  of  going  public, 
according  to  Alec  Ellison,  a  managing  direc¬ 
tor  at  Broadview  International,  a  mergers 
and  acquisition  investment  bank  headquar¬ 
tered  in  Fort  Lee,  N.J.  “The  IPO  is  not  an 
end;  it’s  a  second  startup,”  Ellison  says. 
“Companies  need  to  continue  building  the 
company  and  organization  going  forward.” 
That  message  carries  even  greater  weight 
given  Wall  Street’s  recent  moodiness. 

Obviously,  CIOs  are  instrumental  in  that 
mission.  With  many  of  the  newly  public 


10  0  CIO  JUNE  1,  2000 


www.cio.com 


PHOTO  THIS  PAGE  AND  PRECEDING  PAGE  BY  DOUGLAS  WOODS 


DON’T  BURN 
WHAT  YOU  EARN 


Keep  more  of  your  profits  with  Net- HOPPER’S 
unique  Network  Test  Access  System  (NTAS)™ 

Net-HOPPER  Systems’  NTAS  is  a  unique  and  flexible  architecture  that  enables  network  engineers  to  quickly  and 
easily  troubleshoot  and  maintain  peak  performance  of  their  mission  critical  networks.  Our  customers  prefer  NTAS 
“hands  down”  as  a  more  cost-effective  alternative  to  buying  large  numbers  of  diagnostic  tools, 

and  dedicating  one  to  every  critical  network  segment. 


To  learn  more  about  our  solutions,  please  visit  our  website  at  www.net-hopper.com 


TAS™:  Network  Test  Access  Systems 

...a  simple  solution  for  a  complicated  problem! 


software 


t$L.  <$l 


net-HOPPER 

SYSTEMS.  INC. 

Test  Access  at  Lightspeed 

www.nct-hopper.com 


Net-HOPPER  Systems,  Inc.  330  Research  Court,  Norcross,  CA  30092 


1-800-350-5540 


Web  Business 


companies  focused  on  e-commerce,  the  post- 
IPO  cash  infusion  is  often  used  to  acquire 
companies  or  new  technologies  that  can  pro¬ 
vide  a  competitive  edge.  Technology  execu¬ 
tives  are  often  one  of  the  principal  players 
helping  to  decide  which  companies  to 
acquire  or  invest  in.  Access  to  capital  to  fund 
these  efforts  and  deliver  on  the  strategic 
vision  is  probably  the  best  news  about  life 
post-IPO.  WebMethods,  for  example,  raised 
somewhere  on  the  order  of  $165  million, 
and  Merrick  says  that  currency  will  allow  it 
to  make  acquisitions  that  would  have  been 
extremely  difficult  to  pull  off  otherwise. 

The  cash  infusion  from  an  IPO  also  gives 
technology  leaders  the  flexibility  to  out¬ 
source  operational  IT  functions  and  assign 
internal  staffers  to  projects  that  will  help 
the  company  deliver  a  competitive  edge — 
for  example,  adding  personalization  and 
customization  capabilities  to  an  e-commerce 
site  or  building  a  multimillion-dollar,  inte¬ 
grated  ERP  and  customer  relationship  man¬ 
agement  systems. 


Yet  along  with  the  good  side  of  post-IPO 
existence  comes  the  bad.  Publicly  traded 
companies — whether  they’re  at  the  top  of 
their  game  or  struggling  to  push  their  stock 
price  back  up  to  IPO  levels  and  above — have 
to  contend  with  living  under  the  watchful 
eye  of  Wall  Street,  explaining  every  move 
and  how  it  relates  to  the  corporate  mission. 
“Everything  is  public  now — we’re  scruti¬ 
nized  on  a  daily  basis,”  says  Nathan  Schul- 
hof,  president  and  CEO  of  Audiohighway 
(www.audiobighway.com),  a  website  that 
delivers  free  audio,  video  and  entertainment 
content  to  consumers.  (See  “Life  Is  a  High¬ 
way,  Page  108).  “I  get  30  calls  from  brokers 
a  day  when  the  stock  price  goes  down,  telling 
me  what  we  should  be  doing.  But  we’ve  got¬ 
ten  a  lot  of  money  to  make  our  dreams  come 
true,  so  I  suppose  that’s  the  price  you  pay.” 

These  so-called  suggestions  from  the 
investment  community  can  be  a  real  distrac¬ 
tion  to  the  core  IT  mission,  according  to 
CIOs  in  several  post-IPO  companies.  Say 
Wall  Street  and  investors  get  fixated  on  auc- 


a  number  of  other  challenges,  including  the 
issue  of  hiring  and  retaining  talent,  especially 
hard-to-find  IT  professionals.  With  the  aver¬ 
age  lock-in  period  restricting  employees  from 
selling  stock  from  anywhere  between  six 
months  to  one  year  post-IPO,  many  compa¬ 
nies  are  finding  it  difficult  to  retain  employees 
when  competitors  are  promising  a  fresh  run 
at  a  better  IPO,  and  an  internet  fortune 
appears  to  be  perched  on  every  comer. 

“It’s  tough  because  a  lot  of  this  is  relatively 
unprecedented — to  have  so  much  stock  hold¬ 
ings  among  employees  and  so  much  of  com¬ 
pensation  packages  tied  to  that  as  well,”  notes 
Ken  Andersen,  managing  editor  of  Venture- 
Wire,  a  daily  e-mail  newsletter  covering  the 
high-tech  and  venture  capital  community 
published  by  Technologic  Partners  in  New 
York  City.  “You  have  to  stress  the  importance 
of  when  times  are  good,  not  to  get  too  caught 
up  in  the  stock  price  so  that  inevitably  when 
times  are  bad  you’ve  created  feelings  that  go 
beyond  the  value  of  the  stock.” 

To  do  that,  company  leaders  need  to  foster 


“We  have  to  be  careful  where  we  leave  business  plans 
because  even  the  Xerox  repairman  owns  stock.” 

-Mark  Walsh,  CEO,  VerticalNet 


“The  best  thing  about  going  public  is 
you  get  liquidity,  which  means  you  can  use 
your  stock  as  a  tool  to  either  incentivize 
employees  or  acquire  companies  [or  tech¬ 
nology],”  says  Jason  McCabe  Calacanis, 
CEO  and  editor  of  the  Silicon  Alley 
Reporter,  a  New  York  City-based  publica¬ 
tion  focusing  on  internet  companies. 

And,  of  course,  you  can’t  totally  ignore 
the  financial  aspect.  A  lot  of  companies  that 
venture  into  the  public  market  bring  some 
financial  reward  to  pre-IPO  employees,  and 
often  for  post-IPO  hires  who’ve  been  lucky 
or  smart  enough  to  negotiate  reasonable 
terms  on  their  options.  While  these  employ¬ 
ees  might  not  make  an  instant  fortune,  many 
are  assured  of  a  reasonable  profit. 


tion  technology,  for  example,  because  the 
stocks  of  players  in  that  arena  are  on  an 
upswing.  Outside  pressure  from  top  man¬ 
agement  to  respond  to  Wall  Street’s 
demands  means  CIOs  need  to  do  due  dili¬ 
gence  and  explore  the  possibilities  even  if 
they  later  determine  the  technology  isn’t  a 
fit  for  the  corporate  vision.  “It’s  not  like 
investors  or  the  board  of  directors  force 
something — it’s  just  the  general  mentality 
of  when  the  stock  isn’t  performing  to  try  this 
or  try  that,”  notes  Bill  Weatherwax,  Audio¬ 
highway’s  executive  director  of  product 
development  and  engineering. 

For  companies  like  Audiohighway  that 
are  trading  below  their  IPO  stock  price 
(referred  to  as  options  underwater),  there  are 


a  community  spirit,  giving  employees  a  feel¬ 
ing  of  accomplishment  and  a  sense  of  team¬ 
work  that’s  unconnected  to  whether  the  out¬ 
side  world  responds  positively  or  negatively 
to  the  stock.  “If  people  believe  in  the  mission, 
and  you  can  make  them  feel  like  their  con¬ 
tribution  is  recognized  and  valued,  they’re 
not  going  to  leave,”  Calacanis  says.  “Success 
is  defined  by  the  individual — for  some,  suc¬ 
cess  is  having  $100  million  in  the  bank;  for 
others,  it’s  going  to  a  job  they  love.” 

If  you  consider  today’s  high  standards, 
most  professionals  are  in  search  of  a  dotcom 
nirvana  that  encompasses  both. 

Here’s  a  look  at  three  companies  that 
have  been  through  an  IPO  and  lived  to  tell 
about  it. 


10  2  CIO  JUNE  1,  2000 


www.cio.com 


©2000  Bowstreet.com,  Inc.  Bowstreet  is  a  trademark  of  Bowstreet.com. 


Talk  about  a  shortcut.  Now  you  can  combine  XML  web  services  from 
companies  anywhere  on  earth  into  your  own  customized  business  web. 
Want  to  add  the  talents  of  a  dozen  other  firms?  Boom,  it's  done.  Suddenly, 
you're  selling  their  stuff.  They're  selling  your  stuff.  And  champagne  corks 
are  flying  everywhere.  Once,  it  took 
months  to  pull  off  partnerships  like 
these.  Now,  it's  just  another  day  on  the 
business  web.  www.bowstreet.com 


bowstreet 


PHOTO  BY  TRACEY  KROLL 


Web  Business 


Have  Money,  Will  Hire 


CYBERI AN  OUTPOST 


If  having  an  undervalued  stock  price  is  a  cloud,  Bob  Bowman,  president  and  CEO  of  e-tailer 
Cyberian  Outpost,  knows  how  to  find  a  silver  lining.  Since  going  public  in  the  summer  of  1998,  Outpost  stock,  which 
went  out  at  $18  a  share,  climbed  to  as  high  as  the  $40s  during  the  1998  holiday  season  and  crashed  to  around  $5.  But 
rather  than  deterring  Outpost  employees,  Bowman  says  the  ups  and  downs  have  fostered  an  all-out  desire  to  achieve. 


“Our  technical  group  is  a  competi¬ 
tive  bunch,”  Bowman  says.  “When  the 
stock  is  low,  they  want  it  higher  and 
they’ll  kill  themselves  to  get  it  there.  In 
a  funny  way,  it’s  a  motivator.” 

With  competition  fierce  in  this  cate¬ 
gory  from  sites  like  Amazon.com, 
Buy.com,  800.com  and  others,  Out¬ 
post  can’t  afford  to  take  its  eye  off  the 
ball,  even  for  a  minute.  That’s  why 
Bowman,  who  came  onboard  last 
October,  believes  it’s  so  important  to 
foster  a  competitive  culture  by  hiring 
the  right  people.  Bowman  looks  for 
hires  who  embody  two  key  qualities: 
integrity  and  energy.  A  50-minute 
interview  will  instantly  reveal  a  fit.  Says 
Bowman:  “We  try  to  hire  people 
excited  about  accomplishment,  who 
know  that  nothing  comes  easy  and 
who  know  that  you  get  out  of  a  com¬ 
pany  what  you  put  into  it.” 

Over  the  last  six  months,  the  Out¬ 
post  IT  group  has  certainly  contributed 
its  share.  Outpost,  which  Bowman 
admits  might  have  been  slightly  behind 
its  rivals  in  technology  six  months  ago, 
has  aggressively  pushed  forward, 
adding  state-of-the-art  e-commerce 
capabilities  such  as  advanced  personal¬ 
ization  as  well  as  web-based  data  ware¬ 
housing.  The  latter  gives  the  dotcom  the 
ability  to  drill  into  customer  buying  pat¬ 
terns  to  deliver  a  customized  shopping 
experience,  serving  up  special  offers 
based  on  previous  purchases.  Outpost 
has  also  invested  in  campaign  manage¬ 
ment  and  marketing  software  to  target 
promotions  at  individual  buyers. 

Despite  the  disappointing  stock 
price,  having  the  resources  to  fund  ini¬ 
tiatives  like  these  as  well  as  to  bring  in 


experienced  talent  is  the  biggest  bene¬ 
fit  of  being  public,  says  Dan  Bachman, 
director  of  business  intelligence,  who 
admits,  however,  that  it  isn’t  always 
easy  to  find  qualified  candidates. 
“Now  we  have  money  to  do  the  things 
we  really  know  are  required  to  move 
forward,”  says  Bachman.  For  exam¬ 
ple,  Outpost  has  purchased  Sagent’s 
data  warehouse  software  and  now  has 
over  25  data  marts  in  production 

Location  Kent,  Conn. 

No.  of  employees 

More  than  200 

Nasdaq  symbol  COOL 

Date  of  IPO  Aug.  5,  1998 

IPO  price  $18 

Stock  price  as  of 

press  time  $5 

www.outpost.com 

mode,  helping  it  analyze  various  types 
of  customer  data.  “The  software  lets  us 
be  proactive  and  react  to  things 
quicker,”  Bachman  says.  “Not  many 
dotcoms  have  gotten  into  [this  kind  of 
technology].” 

Bachman,  who’s  been  at  Outpost 
since  February  1998,  sees  little  change 
in  the  culture  since  the  pre-IPO  days. 
When  he  first  came  to  Outpost — fresh 
off  a  grueling  database  marketing  post 
at  a  newly  public  catalog  company 
where  the  stock  never  took  off — 
Bachman  was  struck  by  the  aggressive¬ 
ness,  yet  strong  camaraderie  among 
employees.  “I  saw  a  young,  bright 


group  of  people,  not  heavy  on  busi¬ 
ness  experience,  but  who  were  very 
aggressive  and  willing  to  try  things 
out,”  says  the  50-year-old  Bachman, 
who  adds  that  he’s  the  old  one  in  the 
crew.  “There  wasn’t  politics,  there 
wasn’t  a  set  way  to  do  things,  it  was  a 
team-oriented  atmosphere.” 

Even  with  its  depressed  stock,  Bach¬ 
man  says  that  team  spirit  is  still  very 
much  alive.  There  are  no  official 
offices,  and  people  keep  shuffling 
around  as  the  company  continues  to 
outgrow  its  space.  While  it’s  not  un¬ 
common  for  employees  to  work  week¬ 
ends,  Bachman  says  the  demands  are 
not  onerous,  and  often,  the  extra¬ 
curricular  work  hours  are  fun.  For  the 
Super  Bowl,  for  example,  Outpost 
functioned  as  the  back-end  order  pro¬ 
cessing  site  for  Computer.com,  which 
bought  ad  time,  and  over  100  employ¬ 
ees  volunteered  to  help  answer  the 
phones,  including  CEO  Bowman.  “We 
ended  up  having  a  party  and  quite  a 
good  time,”  Bachman  says. 

It’s  this  kind  of  atmosphere  that  has 
made  Bachman  enjoy  going  to  work 
again.  And  he’s  confident  that  all  the 
hard  work  will  eventually  be  reflected 
in  Outpost’s  stock  price,  showering 
him  and  his  peers  with  the  financial 
return  they  feel  they  deserve.  Says 
Bachman:  “Everyone  has  the  same 
goal — we  enjoy  what  we’re  doing,  we 
have  a  lot  of  opportunity  building  the 
business,  and  the  ultimate  goal  will  be 
to  pull  it  off  so  that  the  stock  goes  up 
and  everyone  makes  out.” 


To  Cyberian  Outpost’s  Dan  Bachman,  IPO  cash  means 
the  opportunity  to  buy  better  technology. 


10  4  CIO  JUNE  1,  2000 


www.cio.com 


Web  Business 


Silicon  Valley,  Philly-Style 


VERTICALNET 


What  do  you  get  when  you  cross  a  collection  of  the  most  unglamorous, 
industrial  websites  with  an  all-American  Philadelphia  suburb?  One  of  the  hottest  internet 
IPO  success  stories  that’s  been  able  to  stay  grounded  despite  its  phenomenal  growth. 

VerticalNet  owns  55  (and  growing)  web-based  trading  communities,  from  Surface- 
Finishing.com  to  SolidWaste.com,  each  delivering  specialized  content  and  business-to-business 
e-commerce  services  to  partners  in  a  particular  vertical  segment.  The  firm  went  public  in 
February  1999  at  $16  a  share.  Shortly  before  Wall  Street  hit  the  skids,  it  was  trading  in  the 


vicinity  of  $148  after  a  stock  split.  The  150 
or  so  employees  at  the  time  of  the  IPO  were 
all  millionaires — at  least  on  paper — and 
most  of  the  1,000  people  currently  employed 
in  the  Horsham,  Pa.,  upstart  can  expect  a 
more-than-healthy  return  on  their  options 
even  now,  with  the  stock  trading  at  a 
respectable  $5 1 .  Yet  it’s  the  seemingly  mun¬ 
dane  nature  of  what  VerticalNet  does  and 
the  shield  of  its  geography  that’s  helped  CEO 
Mark  Walsh  and  his  team  keep  the  company 
driving  toward  its  mission  to  be  a  key  global 
player  in  the  burgeoning  business-to-business 


marketplace  without  getting  completely  side¬ 
tracked  by  Wall  Street. 

“Being  unsexy  helped  us,”  says  Walsh. 
“And  given  that  we’re  not  in  Silicon  Valley 
or  Silicon  Alley  where  there’s  a  plethora  of 
dotcom  startups  and  options  envy,  there’s 
not  the  same  potential  of  losing  focus.” 

The  challenge  of  keeping  a  post-IPO  com¬ 
pany  fixed  on  its  long-term  business  goals 
in  spite  of  the  distractions  of  Wall  Street,  the 
media  and  the  competition  is  a  common 
refrain  among  the  leaders  of  publicly  traded 
dotcoms.  And  VerticalNet  appears  to  be 


Mark  Walsh  (left)  and  Dean  Sivley  of  VerticalNet  have  ridden  the  stock  wave  and 
learned  that  rapid  growth  can  bring  big  challenges. 


right  on  course.  Using  its  war  chest  of 
$65  million  raised  during  its  IPO,  combined 
with  other  venture  capital  money  and  a 
$100  million  cash  infusion  from  Microsoft, 
the  company  has  embarked  on  an  acquisi¬ 
tion  binge  that  Walsh  says  will  yield  $1  bil¬ 
lion  in  revenues  and  put  it  in  the  black  in 
2000,  up  from  the  $20.7  million  in  sales 
inked  in  1999  with  no  profit.  “Having 

Location  Horsham,  Pa. 

No.  of  employees  around  1,000 

Nasdaq  symbol  VERT 

Date  of  IPO  Feb.  10,  1999 

IPO  price  $16 

Stock  price  as  of  press  time  $51 

www.verticalnet.com 

money  is  one  of  the  key  differentiators  of 
business-to-business  websites,”  notes  Walsh. 
“You  have  to  have  cash  available  to  pay  for 
what  it  takes  to  grow  quickly.” 

So  fag  VerticalNet  has  used  its  reserves  to 
buy  numerous  vertical  communities,  includ¬ 
ing  NECX  Global  Electronics  Exchange,  a 
marketplace  for  the  electronics  industry,  as 
well  as  technology  companies  like  Tradeum, 
a  San  Francisco  maker  of  a  Java-based  plat¬ 
form  for  building  online  marketplaces.  And 
with  all  the  media  hype  surrounding  its  suc¬ 
cess,  VerticalNet  is  constantly  inundated 
with  new  business  proposals  from  startups 
looking  to  strike  that  next  deal. 

Screening  the  deals  often  falls  into  the  lap 
of  Dean  Sivley,  VerticalNet’s  senior  vice 
president  of  product  development  and 
e-commerce.  He  says  the  ever-increasing  vol¬ 
ume  of  calls  from  potential  partners — now 
up  to  five  or  six  a  day — has  definitely  ham¬ 
pered  his  ability  to  keep  focused.  “When 
you’re  pre-IPO,  you’re  totally  intent  on 
what  you’re  trying  to  do — there’s  not  a  lot 
of  room  for  other  things,”  he  explains. 
“Now,  it’s  a  challenge  to  keep  up  with 
checking  all  this  stuff  out  and  trying  to  sort 
through  what’s  important.” 

Other  issues  resulting  from  VerticalNet’s 
rapid-fire  growth  are  how  to  prioritize  and 


10  6  CIO  JUNE  1,  2000 


www.cio.com 


PHOTOS  BY  BILL  CRAMER 


COMPARING  PORN  SITES 
FOR  ARTISTIC  MERIT 


DOWNLOADING  "IT^ 
A  POLKA  PARTY!"  CD 


WORKING,  BUT  SLOWED  BY 
CHOKED  BANDWIDTH 


Bandwidth  usage 


or  bandwidth  abusage? 


Telemate  can  tell  you. 

The  Internet  is  an  essential  business  tool.  But  employees  surfing  non-business-related  sites  can  eat  up  bandwidth. 
Service  quality  suffers.  Productivity  slips.  Network  expenses  soar.  NetSpective™  from  Telemate.Net  provides  critical 
information  that  lets  you  monitor,  analyze  and,  more  importantly,  manage  Internet  usage.  NetSpective  goes  beyond  simple 
summaries  to  give  you  details  that  show  exactly  which  sites  individual  employees  visit.  We  extract  this  data  from 

_  ,  leading  firewalls  and  proxy  servers,  and  build  a  data  repository  using  a  robust,  embedded  SQL  database. 

IHTERNET 

USAGE  \  You  can  even  integrate  telephone  usage  information.  To  learn  more,  call  1-800-791-1015.  Or  visit 
POLICY  i  www.yourwhitepaper.com  KEY  CODE  1015  and  download 

T0|pmofe-NeT^  f  .  n  «i  .  *  it  pi-  t 

Te  . .  a  free  copy  of  our  White  Paper  Internet  Usage  Policy. 

'  SOFTWARE 


Web  Business 


manage  IT  projects,  Sivley  says.  To  help 
introduce  process  into  the  IT  organization 
the  company  brought  in  Microsoft’s  Solu¬ 
tions  Framework.  “People  were  hurting 
being  here  until  midnight  every  night  and 
on  weekends,”  he  explains.  With  no  formal 
release  schedules  and  a  set  of  constantly 
changing  requirements,  the  development 
process  has  been  slightly  chaotic  both  before 
and  after  the  IPO,  Sivley  says.  The  Microsoft 
software  helped  to  rein  it  in  by  providing 


structure  and  process.  Some  of  the  core  proj¬ 
ects  Sivley’s  teams  are  pursuing  are  store¬ 
fronts,  e-commerce  centers  as  well  as  lead 
generation  and  lead  management  tools. 

It’s  this  ability  to  invest  in  what  it  takes 
to  get  the  job  done  that  Walsh  insists  is  the 
best  part  of  being  public.  What’s  the  worst 
part?  “The  unbelievable  attention  on  short¬ 
term  goals,”  he  says.  “I  have  to  make  sure 
that  everyone  understands  that  VerticalNet 
gets  a  new  report  card  every  90  days  [when 


quarterly  reports  come  out].  There’s  no 
equity  on  past  report  cards.” 

There’s  also  the  incredible  attention  now 
that  VerticalNet  is  the  hottest  thing  going  in 
Horsham.  “We  have  to  be  careful  what  we 
say,  even  to  each  other.  We  have  to  be  care¬ 
ful  where  we  leave  business  plans  because 
even  the  Xerox  repairman  owns  stock,” 
Walsh  says.  “We  used  to  be  just  a  scrappy 
upstart,  now  we  have  to  walk,  dress  and 
behave  the  part.” 


Life  Is  a  Highway 


AUDIOHIGHWAY 


There’s  a  story  Nathan  Schulhof  likes  to  tell  Audiohighway  employees  as 
a  sort  of  parable  about  the  qualities  and  values  he  thinks  are  critical  to  succeed  in  the  inter¬ 
net  age.  As  a  struggling  law  student  in  San  Francisco  during  the  ’70s,  Schulholf  frequented  a 
cheap  eats  called  The  Haven.  For  two  years,  he’d  slide  his  tray  over  a  3-foot-long  stained- 
glass  light,  where  he’d  stop  and  decide  whether  to  go  for  half  of  a  tuna  sandwich  at  lunch 
and  have  money  left  over  for  dinner  or  do  a  noontime  pig-out  and  sacrifice  the  next  meal. 


Years  later,  as  a  thriving  entrepreneur, 
Schulhof  went  to  check  out  a  beach  house 
he’d  just  purchased  in  Stinson  Beach,  Calif. 
Much  to  his  surprise,  he  saw  the  same  light 
as  part  of  the  house  decor.  The  owner,  who 
turned  out  to  be  the  former  proprietor  of 
The  Haven,  sold  Schulhof  the  light,  which 
now  serves  as  the  Audiohighway  CEO’s 
main  source  of  inspiration.  “In  the  worst  of 
times,  I  look  at  it  and  I  know  that  if  the 
vision  is  right,  you  can  persevere — you  just 
have  to  stay  on  it,”  says  Schulhof. 

As  the  head  of  a  public  dotcom  that’s  cur¬ 
rently  trading  below  its  IPO  stock  price, 
Schulhof  has  certainly  put  that  philosophy 
to  the  test.  Audiohighway,  a  6-year-old  com¬ 
pany,  now  entirely  web-based,  offers  free 
audio,  video  and  entertainment  content  to 
consumers  as  well  as  other  services  such  as 
news  and  voice  mail.  The  company,  which 
was  started  with  $7  million  in  seed  funds 
that  Schulhof  raised  from  150  friends  and 
family  members,  went  public  in  December 
1998,  months  after  an  initial  IPO  slated  for 
August  the  same  year  was  scrapped  mid¬ 


roadshow  because  of  a  huge  stock  market 
slide.  Audiohighway’s  stock  went  out  at 
$6.50  a  share,  was  as  high  as  $38  around 
the  first  quarter  of  last  year,  and  now  has 
fallen  to  $3. 

With  most  of  his  employees’  options 
underwater,  Schulhof  and  his  executive  team 
face  the  tough  job  of  pushing  forward  with 

Location  Cupertino,  Calif. 

No.  of  employees  around  80 

Nasdaq  symbol  AHWY 

Date  of  IPO  Dec.  17,  1998 

IPO  price  $6.50 

Stock  price  as  of  press  time  $3 

www.audiohighway.com 

the  company’s  vision — to  be  a  global  enter¬ 
tainment  site — while  keeping  employees 
motivated  and  challenged.  “Managing 
expectations  of  our  workforce  and  attracting 
and  maintaining  employees  is  the  key  thing 
on  our  plate,”  says  Greg  Sutyak,  Audiohigh¬ 


way’s  CFO.  “What  we’re  finding  is  a  double- 
edged  sword — with  the  stock  low,  there’s 
tremendous  room  for  growth,  but  it’s  easy 
for  other  companies  to  pick  off  employees 
because  there’s  not  a  lot  holding  people  here 
other  than  their  job  and  wanting  to  work  in 
a  particular  segment  of  the  industry.” 

Recruiting  IT  professionals  is  particularly 
tough.  “When  our  staff  sees  people  all 
around  with  more  valuable  options,  they 
start  thinking,  ‘Why  am  I  working  Satur¬ 
days,  why  am  I  doing  this?”’  says  Bill 
Weatherwax,  executive  director  of  product 
development  and  engineering,  who  joined 
Audiohighway  this  January.  Weatherwax, 
who  left  another  internet  startup  shortly 
before  it  went  public,  uses  his  own  situation 
as  part  of  the  sales  pitch.  With  the  stock  price 
under  or  hovering  around  where  it  was  at 
the  IPO,  Weatherwax  plays  up  the  opportu¬ 
nity  to  join  a  public  company  at  a  place  that’s 
almost  like  being  there  on  Day  1. 

On  a  personal  level,  being  a  technology 
manager  in  a  post-IPO  firm  lets  Weatherwax 
tackle  more  strategic  issues  like  team  build¬ 
ing,  keeping  projects  on  track  and  creating 
a  technology  culture  instead  of  the  down- 
and-dirty  programming  role  IT  plays  in  pre- 
IPO  days  when  the  primary  goal  is  getting 
product  out  the  door.  With  technology  at 
the  center  of  most  projects,  Weatherwax 
admits  to  feeling  stretched  at  times.  “I’m 
constantly  being  brought  in  to  provide  tech¬ 
nical  perspective  on  ideas,  which  can  take 
you  away  from  your  core  focus — which  for 


10  8  CIO  JUNE  1,  2000 


www.cio.com 


MISSION 

Implement  a  secure 
e-business. 


SgSfepw 

H  |l 


Things  change.  There’s  a  golden  opportunity  to  grow  the 
business  globally.  Produce  a  new  product  line  by  collaborating 
with  outside  suppliers,  partners  and  key  customers. 
Objectives:  Attract  new  customers.  Corner  the  market. 
Increase  revenues.  Provide  sensitive  data  while  keeping  it 
secure.  The  solution  is  Tivoli®  SecureWay®-  to  let  the  right 
outsiders  share  applications  and  access  critical  corporate 
information.  Create  a  true  e-business  and  keep  it  safe  and 
secure.  With  quick  and  affordable  implementation.  That’s 
why  leading  businesses  choose  the 
award-winning  Tivoli  SecureWay 
solution  from  Tivoli  Systems 
Inc.,  an  IBM  company.  Mission 
accomplished.  1-888-TIVOU-l 
www.tivoli.com/security 

iriW// 

Manage.  Anything.  Anywhere." 


Web  Business 


Audiohighway’s  Nathan  Schulhof 
tries  to  keep  employees  motivated 
despite  a  depressed  stock  price. 

us  now  is  an  e-commerce  redesign,”  he  says. 

Culture  is  critical  at  Audiohighway,  and 
Schulhof  is  a  big  fan  of  team  building,  job 
development  and  perks  to  keep  employees 
happy  and  sheltered  from  the  ups  and 
downs  of  Wall  Street.  Schulhof  has  regular 
meetings  with  employees,  pays  competitive 


salaries  and  full  health  care  for  entire  fami¬ 
lies  and  sponsors  regular  community  events 
like  Team  Building  night.  The  last  one  was 
held  in  March  2000,  when  the  company 
took  over  Emile’s  restaurant  in  San  Jose, 
Calif.,  for  cooking  lessons  and  dinner  with 
its  chef. 

Yet  Schulhof  has  been  around  long 
enough  to  know  that  even  the  best  benefits 
can’t  completely  make  up  for  Audio¬ 
highway’s  sagging  stock  price.  “Sure,  the 


stock  price  pisses  me  off,  but  I  don’t  focus 
on  it,”  he  says.  “I  know  in  my  heart  that  if 
we  stick  to  the  company’s  goals  and  get  the 
projected  results,  the  stock  will  take  care  of 
itself.  I’m  a  pit  bull,  and  I  won’t  give  up  until 
we  finish  the  job.”  QEI 


Had  an  interesting  post-IPO  experience?  Let  Senior 
Writer  Meg  Mitchell  know  at  mmitchell@cio.com. 
Freelance  writer  Beth  Stackpole  can  be  reached  at 
bstack@stackpolepartners.com. 


110  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  KENT  HANSON 


Oupu  Approach  to  BzS 

Appc^u-  • 


Fortunately,  Secure  Computing  takes  an  entirely  different 
approach.  Our  security  products  provide  the  most  flexible 
solutions  for  authenticating  and  authorizing  users  at 
the  first  moment  of  contact  -  no  matter  how  big 
your  network  gets  or  how  many  people  are  using  it.  This  scalable  approach  represents  a 
breakthrough  in  e-security  -  one  where  the  ideal  solution  is  no  longer  measured  by  how 
many  people  you  keep  out,  but  by  how  many  you  escort  in.  For  more  information, 
visit  our  Web  site  today.  www»sectir©coinpiitiiig»c©ni 


Safe,  secure  extranets  for  e-business.  ™ 


A  secure  extranet  that's  always  open  for  e-business  gives 
you  clear  advantages.  But  what  about  when  you  need 
a  solution  that  scales  to  thousands  or  even  millions  of 
users  every  day?  One  thing's  for  sure:  traditional  security 
technology  won't  come  through  for  you.  Your  gateway  will 
turn  into  a  chokepoint,  slowing  your  Web  site  and 
discouraging  your  customers.  If  that  happens,  you're  toast. 


©  2000  Secure  Computing  Corporation.  All  Rights  Reserved. 


Interview 


Steve  Baldwin  and  Bill  Lessard 


The  authors  of  Net  Slaves  pay  tribute  to  the 
unheralded  victims  of  the  dotcom  revolution 


t  all  started  with  two  guys,  an  idea  and  a  website. 
When  Bill  Lessard,  34,  and  Steve  Baldwin,  43,  were 
working  together  at  Time  Warner’s  Pathfinder  in  1996 
(Baldwin  was  a  technology  editor  and  Lessard  was 
a  communications  producer),  they  found  out  why 
the  technology  industry  didn’t  sit  right  with  them: 
long  hours,  high  stress,  zillions  of  dollars  disappearing  into 
doomed  projects  and  an  unbelievable  amount  of  hype  that 
most  people  bought  into. 

After  enduring  job  after  job  in  the  underbelly  of  the  tech¬ 
nology  industry— Lessard  tore  through  seven  in  as  many 
years  working  at  what  he  calls  “some  of  the  most  fabulous 
disasters  in  the  history  of  the  internet,”  and  Baldwin 
bounced  around  the  world  of  technology  publishing  enough 
times  to  leave  bruises— the  two  decided  to  get  together  and 
write  about  what  they’d  witnessed.  To  get  fodder  for  the 
manuscript,  they  started  www.netslaves.com,  a  site  where 
others  could  share  their  stories.  “We  wanted  to  gather 
enough  facts  to  see  if  we  were  the  only  two  losers  in  the 
world,”  says  Baldwin.  Good  news:  They  weren’t. 

112  CIO  JUNE  1,  2000  •  www.cio.com 


BY  MEG  MITCHELL 


PHOTOGRAPHY  BY  STEVEN  VOTE 


interview  I  Steve  Baldwin  and  Bill  Lessard 


And  Net  Slaves:  True  Tales  of  Working  the  Web  (McGraw-Hill, 
1999),  which  emerged  after  the  website  started  attracting  atten¬ 
tion,  is  full  of  those  stories — tales  that  are  engaging,  hilarious  and 
tinged  with  despair.  (Names  have  been  changed  to  protect  the  inno¬ 
cent  and  the  less-than-innocent,  but  one  doesn’t  have  to  think  too 
hard  to  identify  the  guy  with  the  “standard  geek-issue,  bowl-shaped 
cut”  who  just  happens  to  be  the  head  of  a  leading  software  com¬ 
pany  in  Bellevue,  Wash.)  There’s  Jane,  a  freelance  HTML  coder 
who’s  blamed  when  faulty  software  announces  that  O.J.  Simpson 
has  been  declared  guilty  after  the  criminal  trial  jury  finds  him  inno¬ 
cent.  There’s  Officer  Kilmartin,  who  trolls  the  chat  rooms  and  bul¬ 
letin  boards  of  a  popular  online  service  to  make  sure  illicit  mater¬ 
ial  doesn’t  sully  its  family-friendly  image.  There’s  Boyd,  who  leaves 
his  job  in  a  porn  shop  to 
take  a  hellish  help-desk 
position  that  makes  his 
former  occupation  look 
like  a  stay  at  the  Ritz- 
Carlton.  None  of  these 
characters  strikes  it  rich; 
many  of  them  barely  make 
a  living.  And  they  have 
one  thing  in  common: 

They  are  members  of  the 
class  of  net  slaves,  the 
stage  hands  who  labor 
long  after  the  internet  stars 
have  gone  home. 

Lessard  and  Baldwin  di¬ 
vide  the  net  slaves  into  cat¬ 
egories,  such  as  garbage- 
men  (quality  software  en¬ 
gineers),  social  workers 
(bulletin  board  discussion 
leaders)  and  cab  drivers 
(freelance  HTML  pro¬ 
grammers).  With  each  cat¬ 
egory  comes  a  list  of  char¬ 
acteristics:  fry  cooks,  who 
sweat  it  out  in  the  startup 
kitchens  and  enjoy  litera¬ 
ture  “written  by  an  angry  loner  on  the  verge  of  cracking  up”;  cyber 
cops,  who  live  at  home  with  their  parents;  and  their  nemeses,  the 
street  walkers,  who  are  all  about  to  close  on  waterfront  condos. 
The  higher  up  the  caste  system  you  go,  the  fewer  members  there 
are.  While  garbagemen  comprise  40  percent  of  the  internet  popula¬ 
tion,  robber  barons  (self-explanatory,  that  one)  make  up  0.1  percent. 

But  while  the  stories  are  entertaining,  the  message  they  convey  is 
grim:  Somewhere  along  the  line,  things  went  wrong  with  this  inter¬ 
net  economy.  CIO  talked  to  the  authors  of  Net  Slaves  to  find  out  why. 


CIO:  Why  did  you  decide  to  stop  working  in  the  technology  indus¬ 
try  and  start  writing  about  it? 

Lessard:  Do  you  know  what  the  definition  of  insanity  is?  It’s  doing 
the  same  thing  over  and  over  again  and  expecting  different  results. 
A  lot  of  people  who  criticized  us  and  the  book  have  called  us 
whiners.  They  say,  “Why  don’t  you  just  go  get  another  job?”  Well, 
we’ve  done  that  over  and  over  again.  But  the  problem  is  that  no 
matter  where  you  go,  companies  are  struggling.  What  we  tried 
to  do  with  the  book  is  demythologize  the  entire  industry  and  bring 
to  the  forefront  the  people  who  are  really  doing  the  work.  We  got 
tired  of  going  to  parties  where  people  would  say,  “What  do  you 
do?”  and  then  expect  $30  million  to  fall  out  of  your  pocket  if  you 
said,  “I’m  in  the  technology  industry.” 

We  got  the  idea  for  the 
book,  we  interviewed  some 
people,  we  sent  it  out,  and 
none  of  the  publishers  were 
interested:  It  was  too  nega¬ 
tive,  it  was  too  nichey,  who 
cares  about  a  bunch  of 
geeks,  blah  blah  blah.  So, 
just  short  of  jumping  off  a 
bridge  with  cables  around 
our  necks,  we  put  up  the 
website  and  it  took  off. 


BILL  LESSARD 


iOlNG  TO  PARTIES  WHERE  PEOPLE 

would  say,  ‘What  do  you  do?’  and  then  expect 

$30  MILLION  TO  FALL  OUT  OF  YOUR  POCKET 

if  you  said,  ‘I’m  in  the  technology  industry.’ 


You  tell  some  pretty  sobering  stories  of  net  slavery.  Why  is  this  all 
happening? 

Lessard:  There’s  a  lot  of  money  at  stake.  It’s  a  gold  rush  mental¬ 
ity — people  are  very  greedy  and  ethically  challenged,  and  a  lot  of 
abuses  have  come  out  of  it.  We’ve  kind  of  turned  entrepreneurship  into 
rock  and  roll.  It’s  like  CNBC  is  the  MTV  of  the  internet  generation, 
and  by  extension,  the  CEO  is  the  rock  star.  If  this  were  the  ’60s  or  the 
’70s  you’d  have  a  bunch  of  people  in  a  house  saying,  “Hey  man,  let’s 
form  a  rock  band,  put  out  an  album  and  make  a  million  dollars.”  Now 


114  CIO  JUNE  1,  2000 


www.cio.com 


jggpISi  ; 

. 


In  time,  all  questions 

OF  THE  UNIVERSE  WILL  BE  ANSWERED. 
IF  YOU  CAN’T  WAIT,  ASK  QUAAN. 

Seek  enlightenment  with  the  most  revolutionary  corporate  Web  self-help  solution 
ever  created — Quaan?  Quaan’s  Context  Vector"’  technology  understands  your  customers’ 
natural  language  questions  and  quickly  sorts  through  your  knowledgebase  to  provide  extremely 
accurate  responses.  Which  improves  customer  satisfaction  and  reduces  your  support 


site  by  calling  I -800-854-7 1  95  or  visit  www.quaan.com. 


Interview 


Steve  Baldwin  and  Bill  Lessard 


« 


it’s  a  bunch  of  people  in  California  who  say,  “Hey  man,  let’s  get  togeth¬ 
er,  form  an  internet  company,  go  public  and  make  a  billion  dollars.” 

The  technology  industry  can’t  be  all  bad,  can  it?  What  are  some  of 
the  good  aspects? 

Baldwin:  One  of  the  things  I  really  loved  was  how  positive  everyone 
was  about  [the  industry].  Whether  or  not  the  product  they  were 
behind  ever  made  them  rich,  everyone  really  believed  in  the  possi¬ 
bilities  of  this  environment.  It  was  tremendously  exciting,  and  it  still 
is,  but  I  think  one  of  the  costs  of  this  is  that  if  you  start  to  complain 
or  if  you  say,  “Why  did  I  work  1 8  hours  a  day  on  a  project  that  went 
belly  up?” — if  you  start 
addressing  the  facts  of 
work  life — very  quickly 


Was  your  objective  in  writing  the  book  to  make  the  enslavers  or  the 
enslaved  take  notice? 

Lessard:  I’d  say  that  it’s  both.  On  one  hand,  we  want  people  in 
this  industry  to  feel  that  they’re  not  alone.  In  the  past  year  or  so 
since  we’ve  had  the  site  up  we’ve  gotten  e-mail  from  all  over  the 
world.  One  of  the  most  poignant  said,  “Until  I  saw  your  site,  I 
felt  like  I  was  the  only  one  in  the  horror  movie  that  had  seen  the 
alien.” 

Baldwin:  The  idea  was  to  try  to  create  a  sense  of  solidarity  or  non- 
aloneness  among  people  who  find  themselves  in  similar  circum¬ 
stances.  That’s  something  we  seem  to  have  struck  a  resonant  chord 
with  on  the  website  and  in  the  book. 


But  some  people  really  are  succeeding  in  this  internet  economy.  What 
do  they  say? 

Baldwin:  People  say,  “You  guys  are  missing  the  boat!  I’ve  got  a 
new  airplane!  I’ve  got  three  new  girlfriends!  I’ve  got  everything. 
And  if  you’re  not  like  me,  you’re  a  loser.”  They  might  be  on  top 
of  the  world  right  now,  but  where  will  they  be  when  they  are  30 
years  old?  There’s  a  lot  of  evidence  to  suggest  that  being  a  rock 
star  Java  guru  or  a  C++  programmer  is  a  young  person’s  game, 
and  you  don’t  have  a  really  long  career  life.  If  you’re  22  or  27  you 
don’t  mind  working  80  or  90  hours  a  week.  Maybe  it  doesn’t  mat¬ 
ter  if  you  drop  off  the  map.  But  once  you  get  to  be  30  or  3 1 ,  you 

want  to  settle  down,  you 
want  to  have  a  family, 
you’ve  picked  up  some 
obligations.  Are  you  still 
willing  to  work  the  80  or 
100  hours  a  week?  And 
will  they  still  want  you? 


Whose  fault  is  all  this? 
Lessard:  We  don’t  want  to 
say  it’s  management’s  fault, 
or  that  it’s  the  venture  capi¬ 
talists’  fault.  People  make 
conscious  decisions.  No¬ 
body  is  holding  a  gun  to 
their  heads  and  forcing 
them  to  be  in  this  industry. 
But  if  someone  mistreats 
[these  workers],  they  should 
not  be  passive  about  it,  they 
should  fight  back. 

Baldwin:  It’s  also  important 
to  arm  yourself  with  infor¬ 
mation  and  do  your  home¬ 
work  ahead  of  time.  The  net 
provides  a  lot  of  resources. 
That’s  the  other  side  of  it 
being  a  small  business.  Companies,  too,  have  reputations.  But  com¬ 
panies  are  also  very  squirrelly.  It’s  sometimes  difficult  to  find  out  what 
a  workplace  culture  is  really  like.  I  would  definitely  go  in  and  inspect 
the  place.  Look  at  the  programmers.  Look  at  the  environment.  Do 
your  homework. 

Is  it  possible  to  work  in  this  industry  and  not  be  a  net  slave? 

Baldwin:  It  is  possible,  but  I  would  say  it’s  certainly  a  challenge  to  be 
able  to  assert  the  kinds  of  claims  one  used  to  make  about  rights.  It’s 
not  like  we  have  a  right  to  a  40-hour  workweek.  We  don’t.  But  peo¬ 
ple  are  still  people.  They  all  have  passions.  They  still  have  negative 
things  about  them.  And  they’re  all  expressed  in  the  workplace. 


you’re  considered  a  non¬ 
team  player,  and  you  have 
to  really  conceal  that  from 
the  world.  It’s  not  really 
mind  control,  but  everyone 
is  so  positive  that  there’s  a 
denial  of  the  rough  edges 
of  this  industry.  And  there 
are  many  rough  edges. 


THESE  YOUNG  CODE  JOCKS  KNOW  THE 

well,  but  there’s  more  to  the  world  than  just  the 

CODE.  THIS  IS  RUNNING  A  COMPANY.  IT’S  NOT  A  GAME.  Jf  J 


116  CIO  JUNE  1,  2000 


www.cio.com 


Staying  fully  trained  and  skilled  on  the  latest  net¬ 
work  TECHNOLOGY  IS  A  MUST.  ONE  MISSTEP  OR  NETWORK 
OUTAGE  AND  THE  ENTIRE  COMPANY’S  KNOWLEDGE  BASE 
COMES  CRASHING  DOWN,  AND  ALONG  WITH  IT,  REVENUES, 
SHARE  PRICE,  CREDIBILITY  AND  REPUTATION. 

VLAB  KEEPS  YOUR  TEAM  ON  THE  CUTTING  EDGE  AND  ALLOWS  THEM 
TO  LEARN  NETWORKING  SKILLS  ANYTIME,  ANYWHERE  ON 

REAL  GEAR.  NOT  SIMULATIONS. 


Real  Gear,  Real  Skills,  Real  Returns 


: 


WWW.MENTORLABS.COM 


1  .877.GETVLAB 


Interview  I  Steve  Baldwin  and  Bill  Lessard 


Lessard:  One  thing  we  tried  to  make  clear  in  the  book  is  that  it’s 
not  a  static  caste  system.  It’s  dynamic.  You  can  reinvent  yourself. 
You  can  move  up  the  food  chain.  So  while  there  are  people  who 
are  killing  themselves,  there  are  others  who  are  doing  just  fine  as 
consultants  or  owners  of  small  businesses. 


Is  net  slavery  a  necessary  evil  of  this  economy? 

Lessard:  No.  I  have  to  go  back  to  the  mantra  that  human  beings 
have  not  changed.  People  can  do  only  about  four  or  five  hours  of 
solid  work  a  day.  The  reason  people  work  so  many  hours  in  the 
internet  industry  is  because  of  disorganization.  For  every  bad  soft¬ 
ware  release,  if  they  had  only  slowed  things  down  a  little  bit,  they 


younger  dotcom  companies  and  managers  might  immensely  ben¬ 
efit  from  it.  And  I  don’t  think  there’s  an  appreciation  of  that.  You 
know,  it’s  a  young  person’s  business.  These  young  code  jocks 
know  the  code  real  well,  but  there’s  more  to  the  world  than  just 
the  code.  This  is  running  a  company.  It’s  not  a  game;  it’s  not  a  vir¬ 
tual  environment.  There  are  a  lot  of  lessons  they’re  going  to  learn 
the  hard  way.  But  people  in  this  business  want  to  make  a  quick 
hit,  make  a  billion  dollars  and  get  out  of  there. 


What  do  people  from  traditional  companies  need  to  understand 
about  net  slavery? 

Lessard:  Those  people  who  do  have  more  traditional  business  val¬ 
ues  should  realize  that  most 


of 


Net  Slaves:  True  Tales 
Working  the  Web 

By  Bill  Lessard  and  Steve  Baldwin 
McGraw-Hill,  1999,  $19.95 


Lessard| 

Baldwin.# 

atofgswfliBy 


wouldn’t  have  to  go  back  and  redo  it.  In  this  economy,  people 
work  longer  and  stupider. 

Baldwin:  Part  of  what  makes  things  inefficient  is  culture.  The  tra¬ 
ditional  way  of  running  an  org  chart,  running  this  hierarchical 
top-down  approval  process — I’ve  seen  companies  that  make  the 
process  two  or  three  times  longer.  I’ve  also  seen  that  at  old-media 
brick-and-mortar  companies  where  they  just  don’t  understand 
how  decisions  need  to  be  reached  for  what  is  essentially  an  iter¬ 
ative  project.  It  doesn’t  have  to  be  this  way.  But  it’s  a  very  young 
industry.  The  railroads  had  been  around  for  years  before  there 
was  any  credible  movement  to  make  them  more  efficient,  safer 
and  unionized.  And  that  ultimately  made  it  difficult  for  railroads 
to  survive.  But  for  a  while  it  was  the  only  way  people  working  in 
the  industry  could  lead  any  kind  of  normal  lives. 


internet  companies  are  cultur¬ 
ally  narrow.  If  you  work  in  the 
IT  division  of  a  bank  or  an 
insurance  company,  everyone’s 
role  is  defined.  There  are  definite 
functions  and  everybody  knows 
what  they’re  supposed  to  do. 
Then  if  you  go  to  an  internet 
company,  nobody  knows  what 
everybody  does.  Everybody  has 
titles  like  Head  Yahoo,  Chief  Ev¬ 
angelist,  Guru;  nobody  knows 
what  they’re  supposed  to  do. 
And  because  startups  are  by  def¬ 
inition  immature  organizations,  the  culture  is  basically  the  cul¬ 
ture  of  the  two  or  three  people  who  started  the  company — in  most 
cases,  technologists.  But  you  need  different  types  of  personalities 
in  order  to  make  a  good  company.  People  should  not  deny  who 
they  are,  where  they’ve  been,  what  their  experiences  are.  At  the 
same  time,  old  school  tech- 


Find  Out  More... 


Hear  More  From  Steve  Baldwin 
and  Bill  Lessard  on  CIO  Radio 
starting  June  7.  Check  out 
www.cio.com/radio. 


How  can  CIOs  emancipate  net  slaves? 

Baldwin:  In  a  certain  way,  CIOs  have  much  more  relevant  experi¬ 
ence  because  they’ve  seen  the  software  cycles,  fought  many  of 
these  battles  and  learned  the  truth:  A  human  being  is  a  human 
being.  They  know  what  happens  to  people  under  pressure.  It’s  a 
shame  that  more  [CIOs]  are  not  brought  in,  consulted  or  listened 
to  because  I  think  they  would  have  a  lot  to  say.  If  they  could  cod¬ 
ify  their  wisdom  and  put  it  into  some  organized  framework,  the 


nology  people  should  real¬ 
ize  that  working  at  internet 
companies  is  a  lot  like  mak¬ 
ing  a  deal  with  the  devil. 

Most  of  what  really  hap¬ 
pens  in  this  industry  is 
underreported  by  the  main¬ 
stream  media.  Companies 
fail  all  the  time.  A  lot  of 
companies  fail.  It’s  safe  to 

say  that  one  in  10  makes  it  to  the  IPO.  Yet  you  have  companies 
that  are  nailing  bunk  beds  to  the  cubicles  and  the  developers  are 
sleeping  there.  And  nobody  sees  anything  wrong  with  that.  That’s 
what’s  really  sick.  HP1 


cio.com 


Do  you  have  tales  of  net  slavery  to  share  with  us?  Senior  Writer  Meg  Mitchell 
wants  to  hear  them  at  mmitchell@cio.com. 


118  CIO  JUNE  1,  2000 


www.cio.com 


PHOTO  BY  FURNALD/GRAY 


W®. 


Wmm&L. 


royalblue  introduces  ChangeManagerim-IT. 


Over  the  years,  your  primary  role  has  been  one  of  managing  costs  and  increasing  efficiencies  for  your 
organization.  Like  most  forward  looking  companies,  you  are  now  turning  to  your  IT  infrastructure 
to  add  further  business  value  through  ERP,  Sales  Force  Automation  and  E-Commerce  initiatives.  As 
revenue  generation  becomes  more  dependent  on  technology,  the  risk  factors  involved  in  managing, 
changing  or  updating  your  IT  environment  grow  exponentially.  Companies  that  are  prepared  to 
embrace  IT  change  will  enjoy  a  significant  competitive  edge  and  for  companies  that  aren’t — the 
results  can  be  disastrous.  ChangeManager-IT  is  software  designed  to  bring  predictability  and 
reliability  to  every  aspect  of  managing  change  within  your  IT  environment.  For  a  free  product  paper 
on  how  royalblue  ChangeManager-IT  can  address  your  concerns,  please  call  1.800.956.1301  or  visit 
us  on  the  Web  at  www.royalblue.com/frontoffice/us. 


©2000  royalblue.  ChangeManager  is  trademark  of  royalblue.  All  rights  reserved. 


royalblue 


ILLUSTRATIONS  BY  LINDA  HELTON 


IT  Architecture 


E-commerce  is  changing  how  IT  plans  and  builds 
systems.  Command  and  control  are  out; 
flexibility  and  collaboration  are  in. 


BY  CONSTANTINE  VON  HOFFMAN 


For  years,  your  company  has  been  keeping  track  of  which  cus¬ 
tomers  order  what  products  from  you.  If  members  of  your  sales 
force  could  get  their  hands  on  that  information,  they’d  be  able 
to  spot  customer  preferences  and  know  which  new  products  to 
recommend.  If  your  design  team  staffers  had  that  information, 
they  could  take  customer  preferences  into  account  when  creat¬ 
ing  new  products.  To  really  capi¬ 
talize  on  this  opportunity,  both  the 
sales  force  and  design  teams  have 
to  keep  each  other  up-to-date  on 
what’s  wanted  and  what’s  in  the 
pipeline. 


Reader  ROI 

►  Learn  how  the  internet  is 
changing  traditional  IT 
departments 

►  Discover  how  the  role  of  enter 
prise  architect  is  evolving 


www.cio.com  •  JUNE  1,  2000  CIO  121 


IT  Architecture 


There’s  a  problem  with  this  scenario, 
however.  The  IT  group  and  web  depart¬ 
ments  are  both  charged  with  coming  up  with 
ways  to  do  this,  and  neither  side  is  offering 
an  approach  that  fits  the  bill. 

IT  first  has  to  figure  out  which  applica¬ 
tions  to  deploy  and  then  train  everyone  to 
use  them;  even  then  people  will  only  be  able 
to  access  information  from  specific,  prop¬ 


erly  connected  company  offices.  However, 
the  information  will  always  be  correct  and 
totally  secure  from  probing  by  anyone  out¬ 
side  the  company.  On  the  other  hand,  this 
approach  presents  your  company  with  high 
training  costs,  a  long  implementation  sched¬ 
ule  and  a  real  hurdle  in  getting  the  informa¬ 
tion  into  the  field. 

For  its  part,  the  web  group  says  it  can  cre- 


At  health-care  network  Yale-New  Haven 
Health  Systems  in  New  Haven,  Conn.,  mov¬ 
ing  the  IT  department  to  a  web  mind-set  has 
meant  more  than  migrating  from  main¬ 
frames  and  LANs  to  the  web.  It  has  also 
meant  going  from  a  situation  in  which  the 
IT  department  determined  what  was  best 
for  everyone  to  one  in  which  the  department 
has  to  share  the  decision-making  power. 


“Being  in  SAN  JOSE  allows  my  group 
to  FOCUS  on  getting  WEB  applications 
up  and  running  QUICKLY.” 

-Brad  Lewis,  manager,  Snap-on  internet  commerce  center 


This  shift  came  to  the  fore  during  a  recent 
web  project.  “We  have  an  old  mainframe 
legacy  system  that  we  use  as  our  principal 
clinical  system,”  says  Mark  Andersen,  Yale- 
New  Haven’s  CIO.  “It  has  taken  a  lot  of 
effort  to  make  that  accessible  [through  the 
web].”  Prior  to  putting  its  systems  on  the 
web,  the  mainframe  was  used  only  for 
accessing  clinical  data — records  and  test 
results — from  Yale-New  Haven’s  facilities. 

Now,  the  system’s  3,300  medical  staffers 
can  access  clinical  and  reference  information 
anytime,  from  anywhere.  This  means  more 
satisfied  physicians,  better  care  for  the 
patients  and  a  savings  payoff  for  Yale-New 
Haven  itself.  For  example,  if  a  patient  has  a 
problem  when  her  primary  care  physician 
isn’t  on  duty,  the  patient  receives  treatment 
from  a  doctor  who  has  never  seen  her  before. 
Before  the  web,  that  doctor  may  have  called 
the  primary  care  physician  and  described  the 
situation  and  patient’s  history  over  the 
phone.  Now  the  primary  care  physician  can 
look  at  the  patient’s  records  from  home, 
access  an  internal  reference  library  and  then 
make  treatment  recommendations  online. 
For  the  organization,  bills  are  now  processed 
faster  because  records  of  services  rendered 


ate  an  application  fast  and  cheaply 
while  making  the  information  ac¬ 
cessible  from  everywhere.  They’ll 
use  a  web-based  front  end  that  will 
cut  down  on  training  costs;  anyone 
with  a  browser  and  a  password  can 
access  and  input  information.  All 
the  web  team  needs  is  for  the  IT 
department  to  download  the  infor¬ 
mation  from  a  legacy  database  onto 
a  Unix  server  every  night.  This  ap¬ 
proach,  however,  creates  a  problem. 
The  IT  department  isn’t  likely  to  go 
along  because  of  the  risk  of  creat¬ 
ing  redundant  and  out-of-sync 
databases,  which  anyone  with  inter¬ 
net  access  may  be  able  to  get  their 
hands  on. 


New  Tricks 

Some  companies  are  solving  this 
architectural  dilemma  by  making 
their  IT  departments  move  on  web 
time.  While  that’s  a  simple  concept, 
implementing  it  means  changing 
the  way  the  IT  department  has 
been  doing  business  pretty  much 
since  its  creation. 


12  2  CIO  JUNE  1,  2000 


www.cio.com 


KNOWLTON 


ON  INTRAS 


“Hill  a  Knowlton  wanted  an  efficient  way 
to  coordinate  1500  staff  and  clients  worldwide,  introspects 
c-business  technology  gave  it  to  us.  The  result  was  HK.net, 
a  secure  extranet  that  lets  us  create  collaborative  work  envi 
ronments  any  time,  anywhere.  Now,  we  have  single¬ 


point  information  management  for  global  cam 
paigns  and  a  Web  interface  easy  for  anyone  to 


Ted  Graham, 

ill  &  Knowlton’s  Knowledge  Manager 


use. 


Nothing  gets  a  business  together 
like  c-business  solutions  from 
Intraspect.  Find  out  all  about  them 
at  our  Web  site.  Or  call  650-943- 
6000  today. 


intraspect 


IT  Architecture 


Both  IT  and  the  WEB  sides  are 
LEARNING  to  get  along  with  each  other 
in  many  ORGANIZATIONS,  often 
because  of  SHEER  necessity. 


are  available  to  all  departments  as  soon  as 
they  are  entered  into  the  system. 

In  technical  terms,  making  this  transition 
first  involved  installing  remote  dial-up  access 
and  then  using  a  suite  of  programs  from 
Citrix  that  integrates  interactive  applications 


into  a  standard  web  browser,  combining  per¬ 
sonalized  web  content  with  managed  appli¬ 
cations.  These  programs  also  allow  Yale- 
New  Haven’s  IT  department  to  manage 
applications  from  the  mainframe. 

Andersen  also  coordinated  an  initiative 


being  run  by  the  hospital’s  marketing 
group  for  external  customers.  This 
has  added  a  health-care  library,  an 
online  referral  and  appointment  ser¬ 
vice  as  well  as  a  subscriber  e-mail 
newsletter  to  Yale-New  Haven’s  web¬ 
site.  Even  though  the  IT  group  keeps 
the  site  up  and  running,  it  no  longer 
dictates  how  things  operate.  Mar¬ 
keting  is  responsible  for  the  site’s  con¬ 
tent,  yet  neither  IT  nor  marketing  can 
change  the  site  without  agreement  and 
cooperation  from  the  other. 

That’s  a  big  change  for  IT  managers 
like  Andersen  who  are  used  to  having 
sole  control  of  an  organization’s  com¬ 
puting  needs  and  IT  architecture.  As 
the  final  arbiters  on  all  things  technical, 
the  IT  managers  used  to  pick  the 
applications  that  were  deployed  and 
made  sure  the  users  were  trained  on 
them.  That’s  not  how  it  works  now 
with  the  web,  Andersen  observes.  At 
Yale-New  Haven,  IT  has  had  to  follow 
the  lead  of  the  marketing  group  in 
terms  of  what’s  needed  on  the  web.  Yet 
IT  enables  the  website  by  providing 
content  from  legacy  systems.  As  a 
result,  Andersen’s  department  has 
more  influence  on  the  kinds  of  appli¬ 
cations  that  are  offered  online. 

Andersen  isn’t  alone  in  playing  catch¬ 
up  to  the  web  development  group. 

Yet  both  IT  and  the  web  sides  are 
learning  to  get  along  with  each  other 
in  many  organizations.  This  newfound 
cooperation  is  often  because  of  sheer 
necessity.  Both  are  being  hit  with  the 
need  to  justify  their  costs.  “There  are 
a  lot  of  pressures  on  these  folks  right 
now.  They’re  short  of  people,  and 
they’re  under  tremendous  pressure  to 
perform  and  provide  valuable  service 
to  the  business  to  justify  their  exis¬ 
tence,”  says  Fred  Meyer,  vice  president  of 
product  management  for  Tibco  Software,  a 
provider  of  real-time  infrastructure  software 
based  in  Palo  Alto,  Calif.  Many  IT  organi¬ 
zations  have  responded  by  becoming  more 
aggressive  about  business-oriented  goals,  says 


124  CIO  JUNE  1,  2000  •  www.cio.com 


Meyer.  And  this  has  meant  IT  has  to  work 
much  more  closely  with  the  web  side. 

Andersen  says  he  has  been  fortunate  in 
that  he  and  Yale-New  Haven’s  head  of  mar¬ 
keting  get  along  very  well.  “Our  relation¬ 
ship  between  the  MIS  and  the  marketing 
groups  is  one  of  the  better  ones  I’ve  ever 
seen,”  says  Andersen.  “They  want  to  get 
stuff  out  there,  and  we  want  to  make  sure  we 
know  how  to  support  it.” 


internally  and  presents  them  with  new 
challenges  that  they  might  not  have  faced 
from  the  traditional  infrastructure.”  And, 
in  addition  to  not  getting  the  funds  and 
limelight,  IT  groups  are  also  kept  out  of  the 
loop,  being  treated  like  the  proverbial 
mushroom — kept  in  the  dark  and  fed,  well, 
a  component  of  fertilizer.  “IT  is,  in  many 
cases,  the  last  to  know  what’s  going  on, 
what’s  being  developed,  what  type  of 


do  one  of  three  things:  create  an  entirely 
separate  web  company — as  when  KBToys 
spun  off  KBKids.com;  outsource  web  func¬ 
tions  to  a  third  party;  or  establish  an 
entirely  new  unit  within  the  company. 
Unfortunately,  none  of  these  approaches 
guarantees  success.  The  separate  company 
may  flounder,  the  third-party  provider  may 
not  understand  the  core  business  processes 
and  the  internal  unit  may  face  serious  oppo- 


FRICTION  between  WEB  and  IT 
groups  is  more  COMMON  than  not. 


Inferiority  Complex 

Most  CIOs  don’t  have  it  as 
good  as  Andersen,  though. 

Friction  between  web  and  IT 
groups  is  more  common  than 
not,  often  as  a  result  of  IT 
jealousy  of  all  the  organizational  attention 
and  funding  devoted  to  the  web  group, 
says  Stephen  Elliot,  an  analyst  with 
Gartner.  “You  would  be  hard-pressed  to 
find  anyone  in  IT  who  wouldn’t  want  to 
work  on  an  internet  strategy  or  anything 
related  to  the  internet,”  Elliot  says. 
“[Working  on  web  initiatives]  helps  them 
hone  their  skills,  gives  them  better  prestige 


impact  it’s  going  to  have  on  the  existing 
infrastructure,”  says  Elliot. 

Another  reason  IT  personnel  are  envi¬ 
ous  of  their  web  group  coworkers  is  that 
many  web  groups  started  out  as  part  of  the 
IT  department.  When  senior  managers  real¬ 
ize  that  the  cultures  and  skills  needed  for  a 
web  group  are,  in  fact,  very  distinct  from 
those  being  used  by  IT,  they  usually  then 


sition  from  within  the  company. 

“If  an  organization  is  created  and  still 
remains  within  the  company,  many  times 
that’s  not  as  effective  as  intended  because  it 
tends  to  alienate  a  lot  of  the  other  pieces  of 
the  IT  organization  that  are  not  connected 
with  that,”  says  Kevin  Mulcahy  of  DMR 
Consulting,  a  provider  of  management  con¬ 
sulting  and  IT  services  in  Edison,  N.J. 


www.cio.com 


JUNE  1.  2000  CIO  12  5 


rr 


IT  Architecture 


Separate  but  Equal 

Snap-on  Tools  has  avoided  this  pitfall.  The 
IT  department  for  the  Kenosha,  Wis. -based 
manufacturer  of  auto  industry  tools  was 
initially  given  the  assignment  of  putting 
transactions  on  the  web.  “Our  initial  e- 
commerce  initiative  was  focused  on  our 
dealers,”  says  Brad  Lewis,  manager  of 
Snap-on’s  internet  commerce  center.  The 
goal  was  to  migrate  the  3,500  dealers  in 
the  United  States  away  from  faxing  and 
calling  in  orders  to  submitting  them  elec¬ 
tronically  twice  a  week. 

Snap-on  launched  the  initial  project  in 
1994,  although  it  took  two  years  for  a 
majority  of  dealers  to  use  it  on  a  regular 
basis.  Snap-on’s  senior  managers  then 
decided  they  could  realize  even  greater  effi¬ 
ciencies  through  the  web.  To  get  that  done, 
they  created  a  separate  web  unit  in  San  Jose, 
Calif.,  far  away  from  the  corporate  head¬ 
quarters.  “[Being  in  San  Jose]  allows  my 


master  builder 

The  job  of  enterprise  architect  isn’t  going  away,  but  it  is  changing 


With  the  web  pressing  IT  to  deploy  applications  at  a  fever 

pitch,  are  there  any  enterprisewide  architects  anymore  who 
sit  down  and  try  to  figure  out  what  a  company’s  needs  will 
be  in  five  or  10  years? 

Since  technology  changes  so  quickly,  it's  impossible  to  predict  what 
anything  is  going  to  look  like  even  just  a  couple  of  years  down  the  road. 
The  only  constants  seem  to  be  that  companies  are  going  to  need  more 
storage  and  more  servers,  but  as  far  as  what  will  be  stored  or  what 
those  servers  will  be  running,  no  one  is  willing  to  hazard  a  guess. 

When  it  comes  to  reading  tea  leaves,  the  architect’s  responsibilities 
have  changed.  Yet  the  job  of  assessing  enterprise  architecture  is  more 
important  than  ever.  Many  companies  have  relegated  the  role  of  architect 
to  choosing  what  applications  and  processes  work  best  to  the  lowest 
level  possible.  Senior  management  has  realized  that  it  no  longer  makes 
sense  for  corporate  headquarters  to  dictate  to  the  area  office  in  Timbuktu 
whether  to  use  Microsoft  Excel  or  Lotus  1-2-3.  The  only  thing  that 
matters  is  that  all  the  different  offices  be  able  to  read  and  use  each 
locale’s  data.  And  that’s  where  the  enterprisewide  architect  comes  in. 

“A  lot  of  organizations  have  given  up  on  having  centralized 
planning,”  says  Fred  Meyer,  vice  president  of 
product  management  at  Tibco  Software.  “They’ve 
still  got  a  centralized  planning  group  but  [it] 
mediates  between  all  the  local  architects.”  Instead 
of  dictating  what  kind  of  architecture  is  used 
locally,  the  planning  group  sets  service  levels  and 
security  measures  on  an  enterprise  level  and 
advises  local  groups  on  how  to  connect  to  the 
corporate  infrastructure. 

In  this  respect,  the  IT  architect  resembles  a  city 
planner.  He  or  she  is  responsible  for  making  sure  the 
gas,  telephone  and  power  lines  are  all  in  place  and  that 
everyone  follows  the  same  standards  when  constructing 
their  buildings,  so  that  someone  moving  from  one  house 
to  another  doesn't  have  to  outfit  their  appliances  with  new 
plugs.  And,  like  a  city  planner,  IT  architects  aren’t  responsi¬ 
ble  for  what  every  building  looks  like. 

As  a  result,  the  planner  now  has  to  have  a  much  more 
strategic  view  of  what  the  company  is  trying  to  do  and  what 
data  needs  to  be  shared  in  order  to  accomplish  its  objectives. 

-C.  von  Hoffman 


12  6  CIO  JUNE  1,  2000 


www.cio.com 


500%  less  reflection* 

minimizes  distractions 
for  improved  efficiency 


Over  300%  better 
brightness  uniformity* 

for  consistent,  true-to- 
life  images 


Over  300%  higher 
contrast  ratio* 

enhances  legibility 
and  fine  detail 


Over  85%  less  glare 

for  less  eyestrain, 
less  fatigue 


Nearly  3  times  greater 
image  sharpness* 

delivers  improved  clarity, 
precision  and  accuracy 


Enhanced  edge-to-edge  clarity* 

accurately  represents  detail  across 
entire  display 


The  new  MultiSync®  FE  Series  flat-screen  CRT  monitors, 

A  brilliant  solution  to  a  glaring  problem. 


Discover  the  flat-screen  difference. 


Now  you  can  eliminate  a  very  real  problem  —  the  screen  glare  and  reflection  that  add  up  to  eyestrain,  fatigue  and  reduced 
efficiency.  Day  in.  And  day  out.  |  Because  now  the  totally-flat  screens  of  the  affordable  new  MultiSync  FE  Series  CRT  monitors 


deliver  what  no  traditional  curved-screen  monitor  can  give  you.  Like  500%  less  reflection.  And  over  85%  less  glare  from  ambient 
light.  What's  more,  that  hard-to-read  text  suddenly  becomes  noticeably  crisper  from  edge  to  edge.  |  The  advantages  are  clear. 


With  less  glare,  higher  contrast  and  virtually  no  curved-screen  distortion,  your  monitor  images  will  be  decidedly  sharper.  And  the 


MultiSync 
"u"  Better 


same  can  be  said  for  the  people  who  use  them.  To  find  out  more  about  our  flat-screen  advantage,  visit  us  at  http://flat.nectech.com 
or  call  (800)  NEC-INFO. 


NEC  Technologies  MultiSync  FE  Series. 


Starting  as  low  as  $200^ 

Flat  screens  for  everyone. 

http://flat.nectech.com 


MultiSync 

FE700™ 


MultiSync 

FE700M™ 


MultiSync 

FE750™ 


MultiSync 

FE950™ 


*  Based  on  tests  conducted  on  the  MultiSync  FE  Series  and  traditional  curved-screen  CRTs  from  other  manufacturers 
t  Estimated  street  price  for  the  MultiSync  FE700 
MultiSync  is  a  registered  trademark.  FE  Series  and  the  NEC  Technologies  icon  are  trademarks  of  NEC  Technologies.  ©2000  NEC  Technologies,  Inc. 


IT  Architecture 


group  to  truly  focus  on  getting  web  appli¬ 
cations  for  e-commerce  and  websites  up  and 
running  quickly  and  efficiently,”  says  Lewis. 
“It  kind  of  took  us  out  of  the  typical  cor¬ 
porate  IT  environment  and  put  us  smack 
dab  in  the  middle  of  Silicon  Valley.” 

Despite  being  thousands  of  miles  away 
from  the  IT  department,  the  e-commerce 
group  is  still  highly  dependent  on  it.  Thanks 
to  the  efforts  of  the  IT  department  and  the 
e-commerce  group  to  integrate  an  online 


everything  from  net  meetings  to  videoconfer¬ 
encing  to  online  project  management  in 
order  to  stay  in  regular  contact  with  his 
counterpart  in  the  IT  department.  He  is  not 
surprised  that  it  has  taken  so  much  work  for 
him  to  get  the  message  across.  “We’re  talking 
about  a  change  in  philosophy,”  he  says. 


In  the  Same  Boat 

It’s  helped  that  Lewis  has 
been  able  to  show  the  IT 


way  street,  Snap-on’s  Lewis  has  one  person 
from  his  16-member  department  working 
at  the  IT  offices  in  Kenosha.  His  job  is  to 
translate  each  group’s  concerns  to  the  other. 
“He’s  on  my  team  but — while  his  job  is  to 
interface  with  this  group  so  that  they  under¬ 
stand  your  needs  and  your  problems — he’s 
kind  of  riding  the  fence:  Some  days  it  looks 


“Most  of  the  FACTS  or  hard  data 

that  are  going  to  be  NEEDED  by 
the  E-COMMERCE  system  are  already 
in  the  SYSTEMS  that  exist.” 


-Larry  Warnock,  VP  of  marketing,  OnLink  Technologies 


catalog  system  with  Snap-on’s  current  ERP 
system,  the  company  now  runs  a  website 
that  personalizes  its  product  catalog  for 
each  customer.  It  adjusts  the  selection  of 
tools  and  prices  depending  on  which  indus¬ 
try  the  customer  is  in  and  what,  if  any,  pric¬ 
ing  agreements  the  customer  has  with  Snap- 
on.  All  of  this  requires  a  lot  of  information 
from  the  IT  department — everything  from 
when  the  latest  tools  are  due  for  release  to 
new  pricing  guidelines.  In  addition,  some 
updates  to  the  website  no  longer  need  to 
go  through  IT.  For  example,  an  employee  in 
the  industrial  division  can  add  a  new  cus¬ 
tomer  to  the  system  by  filling  out  an  online 
form  with  the  customer’s  name,  password 
and  ID  number. 

Getting  this  up  and  running  was  a  very 
frustrating  experience  for  Lewis,  who  rec¬ 
ognizes  that  he  was  asking  IT  to  break  some 
old  habits.  To  keep  his  objectives  on  the 
radar  back  in  Wisconsin,  Lewis  has  used 
every  web  tool  possible  to  shrink  the  physical 
distance  between  the  two  groups — using 


department  what  he  wants  to 
do  and  how  it  will  help  the 
company.  “I  believe  in  proof 
of  concept.  So  I  figure  out  a 
way  to  get  it  done,  and  I  show 
it  to  them  and  say,  ‘Look  at 
this;  isn’t  this  neat?”’ 

In  turn,  one  thing  that  has  made  life  eas¬ 
ier  for  Snap-on’s  IT  department  is  that  Lewis 
and  the  e-commerce  group  understand  how 
much  of  the  content  they  need  is  contained 
in  legacy  databases.  Such  an  understanding 
can  help  the  web  group  and  IT  department 
get  along  at  other  companies. 

“Most  of  the  facts  or  hard  data  that  are 
going  to  be  needed  by  the  e-commerce  sys¬ 
tem  are  already  in  the  systems  that  exist,”  says 
Larry  Warnock,  vice  president  of  marketing 
for  OnLink  Technologies,  a  Redwood  City, 
Calif.,  provider  of  sales  and  marketing  appli¬ 
cations  for  e-commerce.  “So  if  [the  web 
group]  just  looks  at  the  systems  they  have — as 
sort  of  a  great  source  of  data — it  can  coexist.” 

Realizing  that  communication  is  a  two¬ 


like  he  works  for  them  and  some  days  it 
looks  like  he  works  for  me.” 

A  similar  mind-shift  needs  to  happen  at 
organizations  to  bridge  the  gap  between  IT 
and  web  architecture. 

“Once  you  get  done  looking  at  your 
horoscope  and  your  stock  quotes,  if  the 
infrastructure  isn’t  tightly  tied  to  the  web¬ 
site  then  you  don’t  really  have  anything  to 
say,”  says  Meyer.  “That  us-versus-them, 
we’re-building-the-website  and  you-guys- 
go-away-and-do-the-infrastructure  thing 
that  was  common  a  couple  of  years  ago  is 
really  off  the  map  now.”  BE! 

Is  your  IT  group  built  to  move?  E-mail  Senior  Editor 
Megan  Santosus  at  santosus@cio.com.  Constantine 
von  Hoffman  is  a  Boston-based  freelance  writer. 


12  8  CIO  JUNE  1,  2000 


www.cio.com 


mama 


By  picking  a  UPS  scalable  to 
your  network  requirements, 
space,  and  budgetary  needs. 


How  do  you  choose  a  UPS 

when  you  can't  even  guess  how 
many  critical  systems  you'll 
have  to  support  next  year? 


For  over  30  years,  Liebert  has  provided  power  protection  for  the  world’s  most  critical 
systems.  We  designed  the  new  Nfinity "  UPS  to  carry  on  the  tradition  of  Liebert  reliability 
in  today's  critical  network  applications. 

The  modular  design  allows  you  to  configure  Nfinity  to  match  your  changing  power  needs,  and  all  modules  are  hot- 
swappable,  allowing  for  uninterrupted  performance  when  you  service  or  expand  the  system.  You'll  find  redundancy 
and  patent  pending  intelligence  features  in  the  power  and  battery  modules,  power  bypass  systems,  communication 
paths  and  system  controls.  No  other  UPS  achieves  that  tremendous  breadth  of  reliability. 

Nfinity  offers  superior  value.  It's  extremely  cost-efficient  to  operate  and  ships  preassembled  and  pretested,  eliminating 
costly  user  assembly  time.  You're  also  backed  by  Liebert's  service  organization  -  trained  and  staffed  to  support  you 
24x7x365.  For  complete  product  information,  visit  our  website  at  www.nf3.liebert.com. 

Nfinity  -  the  easily  scalable,  incredibly  intelligent,  remarkably  redundant  UPS  that  takes  systems  availability 
to  the  next  level. 


®  2000  Liebert  Corporation.  All  rights  reserved  throughout  the  world.  Specifications  subject  to  change  without  notice. 
All  names  referred  to  are  trademarks  or  registered  trademarks  of  their  respective  owners. 


To  find  your  local  Liebert  Representative 
or  for  information  on  becoming  a  VAR: 


800-877-9222  dept.  NF3 


www.nf3.liebert.com 


info@liebert.com 

0^4  Liebert 

KEEPING  BUSINESS  IN  BUSINESS.® 


13 


Mergers  &  Acquisitions 


Tim  Wright  knows  acquisitions.  As  the 
head  of  technology  at  CD-ROM  publisher 
SoftKey  (which  later  became  The  Learning 
Co.),  he  helped  oversee  more  than  20  of 
them.  Wright  was  also  a  central  observer 
when  toy  maker  Mattel  made  its  ill-fated 
purchase  of  The  Learning  Co.,  which  was 
completed  in  May  1999.  Wright’s  short  stint 
at  Mattel  proved  very  practical;  it  taught 
him  how  not  to  handle  an  acquisition. 

“I  learned  that  above  all  else,  you  don’t 
impose  tight  constraints  from  above,  that 
you  treat  the  staff  you’ve  acquired  with  re¬ 
spect  and  you  keep 


For  Lycos,  the  best  way  to  integrate  new 
companies  under  its  corporate  umbrella 
is  to  help  them  remain  autonomous 


Reader  ROI 

►  Discover  why 
acquiring  internet- 
based  companies 
requires  kid  gloves 

►  Learn  how  to  spot 
technical  red  flags 
before  an  acquisition 


the  products  ship¬ 
ping,”  he  says.  After 
several  months  at 
Mattel,  Wright,  a 
certified  scuba  diver 
and  former  mathe¬ 
matics  lecturer  at 
the  University  of 
West  Indies  in  Lon- 


BY  STEWART  DECK 


don,  began  to  look  for  other  challenges. 

In  November  1999,  he  found  one  when 
web  portal  network  hub  Lycos  came  call¬ 
ing.  The  fast-growing  company  based  in 
Waltham,  Mass.,  was  searching  for  its  first 
CIO.  “They  were  looking  for  someone  with 
experience  in  acquisitions,  someone  who 
knew  how  to  handle  multiple  staffs  of 
skilled  people  and  knew  how  to  blend  dis¬ 
parate  pieces  together,”  he  says. 

When  it  comes  to  acquisitions,  some 
companies  search  for  products,  technolo¬ 
gies  and  services  that  complement  their 
current  product  line;  the  end  result  is  that 
the  acquired  companies  are  swallowed 
whole.  Networking  equipment  giant  Cisco 
Systems  often  brings  its  acquisitions  on 
board  this  way,  blending  them  in  com¬ 
pletely  and  centralizing  all  operations.  “It’s 
hard  to  argue  with  the  results  Cisco  gets,” 


CD 

O 


O 

X 


k. 


mmsi 


Wk 


$fa 'A 


-  ■■  \ 

'  ■ 

sHX&tisftt  >s' '  ■  ' 


For  Lycos  CIO  Tim  Wright, 
giving  acquisitions  free  rein 
is  the  way  to  go. 


Mergers  &  Acquisitions 


says  Jonathan  Poe,  vice  president  and  analyst  in  Stamford,  Conn.- 
based  Meta  Group’s  executive  directions  program.  “Their  successes 
[in  acquisitions]  speak  volumes,”  says  Poe.  This  strategy  is  a  partic¬ 
ularly  good  one  for  Cisco  because  the  company  can  integrate  new 
offerings  into  its  existing  product  line  in  an  effort  to  provide  cus¬ 
tomers  with  a  broad  set  of  tools.  The  skilled  engineers  Cisco  acquires 
can  continue  to  develop  and  advance  the  company’s  products  even 
as  they  are  added  to  the  Cisco  catalog. 

The  Power  of  Confederation 

But  as  Lycos  demonstrates,  there’s  another  way  to  go  about  the  acqui¬ 
sition  game.  While  Lycos  is  quick  to  centralize  back-office  opera¬ 
tions  such  as  human  resources,  payroll  and  accounting,  the  com¬ 
pany  goes  to  great  lengths  to  allow  its  acquisitions  to  maintain  their 
individual  identities.  Lycos  is  discovering  that  letting  acquisitions 
live  on  works  well,  especially  in  the  dotcom  world  where  there  are 
more  independent-minded  entrepreneurs  than  profits. 


“In  managing  an  acquisition,  you’re  really  looking  for  the  sweet 
spot  between  centralization  and  complete  autonomy,”  Poe  says, 
adding  that  too  much  centralization  can  strangle  an  acquired  com¬ 
pany  and  cause  an  exodus  among  the  creative  people  who’ve  just 
been  brought  in.  And  in  the  dotcom  world,  where  creativity  is  the  cur¬ 
rency  on  which  websites  live  or  die,  losing  top-quality,  smart  people 
can  irretrievably  harm  a  company’s  long-term  prospects. 

Lycos’  strategy  is  to  keep  its  acquisitions  of  internet-based  com¬ 
panies  in  a  loose  confederation.  This  tactic  is  designed  to  keep  the 
smaller  companies  nimble — and  to  keep  the  employees  at  those  com¬ 
panies  from  jumping  to  greener,  less  restrictive  pastures.  For  exam¬ 
ple,  Gamesville.com,  a  gaming  and  entertainment  site  Lycos  pur¬ 
chased  in  November  1999  for  $207  million,  has  continued  to  roll 
out  timely  new  games,  including  college  and  professional  basketball 
tournament  contests  that  might  have  been  held  up  completely  if  the 
company  had  been  forced  to  meet  several  layers  of  bureaucratic 
approval.  And  instead  of  being  threatened  by  the  success  of  its  acqui¬ 
sition,  LIotBot,  Lycos  allowed  the  search  site  to 
maintain  its  autonomy  from  the  main  Lycos 
search  directory.  By  doing  so,  Lycos  and  HotBot 
are  both  among  the  web’s  top  10  search  engines 
and  together  draw  more  visitors  than  a  merger 
of  the  two  would  have. 

At  Lycos,  it’s  Wright’s  job  to  weave  the  cor¬ 
porate  technology  pattern  around  acquisitions, 
to  discover  how  best  to  use  technology  and  the 
human  and  network  resources  to  support  the 
autonomous  confederation  of  high-traffic  web¬ 
sites  Lycos  has  acquired. 


Laying  the  Groundwork 

When  Lycos  makes  an  acquisition,  it  does  more 
than  just  sign  an  agreement.  Wright  wants  to 
ensure  that  the  acquired  company  keeps  oper¬ 
ating  normally.  “I  talk  to  the  company  and 
make  sure  it  understands  we  want  it  to  run  busi¬ 
ness  as  usual.  I  don’t  want  to  scare  anyone,  so  I 
try  to  make  [the  employees]  feel  at  home,”  he 
says.  Doing  so  will  begin  to  help  assuage  fears 
of  customers  and  even  employees  who  may 
think  that  everything  will  change  under  new 
ownership.  This  is  particularly  critical  with  inter¬ 
net  businesses  that  derive  much  of  their  value 
from  the  caliber  and  size  of  their  audience. 

Wright  also  brings  up  some  of  the  fringe  ben¬ 
efits  that  come  with  an  association  with  Lycos. 
“We  let  [the  acquired  companies]  know  right 
away  that  we  can  help  them  by  redirecting  our 
traffic  to  their  site  and  recirculating  traffic  back 
their  way,”  Wright  says.  Redirecting  traffic  can 


13  2  CIO  JUNE  1,  2000 


www.cio.com 


EXIT  ! 

IMTfcRVtE  w-$' 


NEw 

HtRsC 


FREE-AGENT  MANIA 


When  you  absolutely  have  to  have  a  B+B  site  engineered  to  perfection, 
or  you've  been  thinking  about  outsourcing  part  of  your  application 
development  or  maintenance. ..or,  you  simply  need  to  augment 
your  staff—  call  us. 

As  a  SEI-CMM  Level  5  company,  Satyam  is  the  better  way. 

Delivering  tomorrow's  IT  solutions  today 

Call  800.450.7605  or  visit  our  website  at  www.safyam.eom 


Satyam 


Mergers  &  Acquisitions 


l 


make  a  tremendous  difference  when  you’re  talking  about  the  Lycos 
network’s  82  million  average  daily  page  views  and  3.5  billion  page 
views  per  month.  By  recently  funneling  and  recirculating  Lycos  net¬ 
work  site  visitors  to  its  new  acquisitions,  Lycos  easily  tripled  the 
traffic  on  both  the  Gamesville.com  and  Quote.com  sites,  Wright 
says.  This  kind  of  traffic  boost  pays  off  handsomely  in  advertising  rev¬ 
enue  for  the  acquired  sites. 

Wright’s  soft  sell  approach  doesn’t  go  unnoticed  by  founders  at 
acquired  companies.  “The  first  thing  Wright  said  to  us  was,  ‘Keep 
doing  what  you’re  doing,  and  keep  your  product  moving,”’  recalls 
Stuart  Roseman,  CTO  and  cofounder  of  Gamesville.com. 

Roseman  has  loved  being  an  entrepreneur  and  enthusiastically 
says,  “There’s  nothing  like  the  excitement  of  building  something 
yourself.”  And  yet,  the  merger  with  Lycos  hasn’t  dimmed  this  inde¬ 
pendent  spirit.  “How  can  being  part  of  the  fourth-most-visited  net¬ 


The  Future  of  Technology 
Starts  Here 

One  advantage  of  working  for  a  sizable  company  like  Lycos  is  that  vendors 
fight  each  other  to  give  the  CIO  sneak  peaks  of  new  technologies.  But 
keeping  track  of  all  these  new  opportunities  is  more  than  one  person  can 
handle,  so  Tim  Wright  has  assembled  a  team  of  bright  technology  enthusi¬ 
asts  from  within  the  company’s  ranks  to  help  him  make  sense  of  vendor 
pitches  and  find  out  what  on  the  technology  horizon  could  benefit  the 
Lycos  network  in  the  future. 

The  group  has  four  full-time  members  who  do  this  exclusively.  Other 
Lycos  staffers  (including  the  chief  of  security)  also  add  their  advice  and 
expertise  to  the  mix.  Their  mission,  says  Wright,  is  to  determine  the  next 
technologies  that  will  help  Lycos  run  more  efficiently. 

To  ferret  out  the  bleeding-edge  technologies  that  will  give  Lycos  a  boost, 
the  group  members  read  plenty,  meet  with  vendors  for  demos,  get  input 
from  colleagues  and  attend  conferences.  Wright  says  the  twice-yearly  Web 
Monster  conference  is  an  especially  useful  one  for  the  group  “because  it’s 
packed  with  web  gurus  and  oddly  intense  technology-obsessed  people." 
Members  also  become  experts  in  specific  areas  and  write  up  white  papers 
on  topics  including  global  network  load  balancing,  service  level  agreements 
and  assessing  security  in  an  effort  to  determine  Lycos’  strengths  and 
potential  weaknesses. 

Many  vendors  have  asked  these  Lycos  future  technologies  team  mem¬ 
bers  to  assist  them  by  serving  on  user  advisory  councils  and  committees. 
Such  an  arrangement  benefits  both  parties.  Vendors  seek  user  insight  and 
input  from  members  of  the  Lycos  team  because  of  their  corporate  indepen¬ 
dence  (Lycos  isn’t  owned  by  a  larger  conglomerate)  and  their  vendor 
neutrality.  And  by  serving  on  advisory  committees  at  Akamai,  Exodus, 
Microsoft  and  Storage  Networks,  Lycos  is  able  to  have  “a  distinct  influence" 
with  its  vendors  on  product  direction  and  development,  Wright  says. 

-S.  Deck 


work  in  the  world  be  a  bad  thing?”  he  asks.  “Has  the  size  held  us 
back,  kept  us  from  being  nimble  and  responding  quickly  to  chal¬ 
lenges,  has  it  somehow  changed  our  entrepreneurial  spirit?  Not  in  any 
way.  We’re  still  doing  our  own  thing,  and  we’re  still  focused  on  con¬ 
quering  the  world.  Being  part  of  Lycos  will  allow  us  to  do  that  more 
easily,”  he  asserts. 

Personnel  Matters 

No  matter  how  big  a  welcome  mat  Lycos  throws  out,  it’s  still  not  easy 
for  other  managers  at  acquired  companies  to  give  up  control.  After 
all,  many  have  an  emotional  stake  in  their  companies,  having  poured 
themselves  into  starting  something  from  scratch.  Wright  is  sensitive  to 
the  hand-holding  that  is  often  required.  “What  you  find  with 
[employees  at]  many  startups  is  intense  loyalty  to  the  application 
they’ve  built  and  to  the  people  who  are  there,”  says  Wright.  “You 
have  to  be  sensitive  to  that  and  try  to  harness  the  passion  and 
the  skills  they  have.  Challenge  them  with  work  and  respon¬ 
sibility  and  help  them  unleash  their  ideas.” 

One  of  the  chief  challenges  in  an  acquisition  is  keeping  the 
good  people  who  have  just  been  brought  on  board.  The 
best  way  to  do  this  is  by  giving  them  professional  develop¬ 
ment  incentives,  such  as  added  network  management 
responsibilities,  additional  certification  training  and  clear 
career  paths  and  goals,  things  they  may  not  have  had  at  a 
startup.  Competitive  pay — not  just  stock  options — will  also 
likely  be  something  they’ll  appreciate  and  something  they 
may  not  have  had  in  a  small  company. 

Another,  perhaps  even  larger  issue  may  be  finding  a  chal¬ 
lenge  for  the  founders.  “Incentivizing  founders  can  be  very 
difficult,”  says  Wright.  “They’ve  just  made  a  snot  load  of 
money  and  now  they  don’t  have  to  work  so  crazily  any¬ 
more.”  While  at  Lycos,  Wright  has  met  founders  who  sub¬ 
sequently  had  little  to  do  after  being  acquired  because  they 
were  no  longer  controlling  day-to-day  operations.  In  some 
cases,  Lycos  has  found  that  it’s  better  to  pay  mavericks  to 
walk  away  entirely  than  to  have  them  stay  on  and  grow  frus¬ 
trated.  “In  some  situations,  the  sooner  you  can  reach  this 
path  of  least  resistance  the  better,”  Wright  says. 

Another  carrot  Lycos  dangles  to  acquired  companies  is 
removing  the  burden  of  administrative  tasks.  Wright  sees  to 
it  that  all  the  mundane,  everyday  worries — including  traffic 
monitoring,  router  and  firewall  management,  server  adminis¬ 
tration,  load  balancing,  database  support  and  even  legal  ser¬ 
vices — are  taken  off  the  shoulders  of  acquired  companies,  leav¬ 
ing  them  to  concentrate  on  site  development.  Doing  this 
allows  Lycos  to  have  some  administrative  oversight  of  the 
new  sites  coming  into  its  network,  while  gaining  some 
economies  of  scale  with  its  own  suppliers. 

But  not  every  acquisition  is  suddenly  given  free  run  of 
the  corporate  candy  shop.  “We’re  a  large  network,  and  each 


13  4  CIO  JUNE  1,  2000 


www.cio.com 


LIKE  HAVING  THE  WISDOM  THAT  COMES  WITH  AGE 


We  entered  the  business  way  before  most  of  our  competitors  took  root. 

As  one  of  Sun  Microsystems’™  oldest  and  largest 

AVCOM  has  earned  its  reputation.  Our  Sun™  Enterprise™  Elite  certified  engineers  have 
an  of  Sun  solutions,  network  design,  Web  architecture, 

databases,  security,  and  more. 


Web  at 
high-end 
or  other 


And  now,  AVCOM  is  branching  out  across  the  country  and  on  the 

Pt  Check  availability,  buy 

solutions  online  and  track  orders  in  real-time-whether  you’re  shopping  for  Sun 
complementary  products  like  Oracle®,  Cisco®  and  VERITAS®. 


of  what  many  pioneering  companies-including  eBay, 
Amazon.com,  E*Trade,  Intuit/Quicken  and  Sch wab-already  have. 
AVCOM. ..every  inch  we’ve  grown  is  an  I.T.  lesson  learned. 


www.avcom.com 


Visit  www.avcom.com/et  to  request  more  information 
and  register  to  receive  a  FREE  monthly  subscription 
to  Enterprise  Technologies. 

Sun,  Sun  Microsystems,  the  Sun  logo  and  Enterprise  are  trademarks  or  registered  trademarks  of  Sun 
Microsystems,  Inc.  in  the  United  States  and  other  countries.  The  AVCOM  logo  and  The  Sun  I.T.  Industry  Portal 
are  trademarks  of  AVCOM  Technologies,  Inc.  All  other  trademarks  are  property  of  their  respective  owners. 


NATIONAL 

SYSTEMS 

PARTNER 

£NT(B»RISE  EUTt 


BEING  AROUND  A  LONG  TIME  HAS  ITS 


ADVANTAGES 


National  Systems  Partners 


unparalleled  knowledge 


www.avcom.com 


ake  advantage 


EXPERIENCE  COUNTS 


CORPORATE  OFFICES:  AVCOM  TECHNOLOGIES,  INC.,  573  MAUDE  COURT,  SUNNYVALE, CA  94086,  TEL:  1  -888-88- AVCOM 


Mergers  &  Acquisitions 


[sire]  believes  that  it  is  the  most  important  piece  to  us,”  Wright  says 
with  a  sigh.  “We’re  also  profitable  and  want  to  stay  that  way,  which 
means  that  there  are  resource  limitations.  Sometimes  I  have  to  say 
no.”  Wright  recalls  explaining  to  other  network  divisions  why  he 
intended  to  spend  marketing  and  promotional  resources  on  newly 
bought  Quote.com  and  Gamesville.com  and  not  on  their  sites  that 
had  higher  visitor  counts;  with  greater  growth  potential  among  the 
newcomers,  it  made  sense  to  invest  in  them. 

Mix  and  Match 

The  Gamesville.com  acquisition  was  exactly  what  Lycos  was  look¬ 
ing  for — an  innovative,  sticky  website  that  had  found  a  way  to  get 
people  to  sign  up  for  targeted  e-mail  direct  marketing  by  tapping 
into  their  gaming  and  entertainment  interests. 

“We’re  now  looking  for  [potential  acquisitions  with]  deep  con¬ 
tent  that  holds  viewers  longer  and  that  can  also  add  to  our  financial 
results,”  says  Ron  Sege,  executive  vice  president  at  Lycos.  Both 
Gamesville.com  and  Quote.com,  a  September  1999  addition,  have 
average  user  session  lengths  of  more  than  an  hour,  and  Gamesville 
.corn’s  business  model — built  around  sophisticated  database  direct 
marketing  to  registered  users — was  particularly  enticing,  both  on  a 
financial  and  technological  level. 

It’s  not  just  finances  and  technology  that  Lycos  takes  into  account 
when  contemplating  an  acquisition.  “We  want  to  make  sure  our 
cultures  are  similar”  before  taking  on  a  new  acquisition,  says  Sege.  “If 
they’re  interested  in  the  [site]  user  experience,  if  they’ve  built  a  great 
infrastructure  and  if  they  either  make  money  or  have  good  potential 
for  making  money,  they’ll  be  a  good  fit.” 

The  acquisitions  planning  starts  long  before  Wright  gets  involved, 
but  his  expertise  is  called  on  to  make  sure  Lycos  isn’t  about  to  pur¬ 
chase  a  technology  mess.  In  any  acquisition,  the  CIO  can  look  for 
potential  trouble  in  several  areas.  If  the  fundamental  business  of  the 


Finding  the  Best 

Another  of  the  first  things  Wright  does  when  Lycos  makes  an  acqui¬ 
sition  is  sit  down  with  the  new  teams  and  learn  what  they  do  well. 
“I  want  to  know  who  we’ve  just  brought  on  board,  what  each  indi¬ 
vidual’s  expertise  is,  what  motivates  him  or  her  and  where  the  core 
expertise  of  the  company  lays,”  Wright  explains.  In  doing  so,  Wright 
determined  that  the  network  operations  center  run  by  Quote.com 
was  just  what  Lycos  needed  for  a  corporate  command  network  mon¬ 
itoring  center.  He  centralized  all  network  monitoring  there  and  reor¬ 
ganized  all  of  Lycos’  disparate  operations  teams  so  that  they  now 
respond  directly  to  this  center  rather  than  to  a  chain  of  command  in 
their  former  company. 

Along  the  same  vein,  Wright  turned  up  a  team  of  reporting 
experts  who  had  joined  Lycos  when  it  spent  $83  million  to  acquire 
Wired  Digital  in  October  1998.  The  team  had  built  a  very  scalable 
and  robust  reporting  and  data  extraction  process  for  Wired  using 
Red  Brick  and  Informix,  so  Wright  put  them  to  work  as  his  core 
enterprise  reporting  team.  Now  all  network  management,  product 
and  traffic  management,  and  financial  reporting  is  centralized  under 
this  one  group. 

In  addition  to  gaming  expertise,  the  purchase  of  Gamesville.com 
brought  on  board  many  skilled  database  developers,  since 
Gamesville.com’s  business  model  depended  on  tailored  database  mar¬ 
keting  campaigns.  Before  the  acquisition,  Lycos  had  its  own  group 
already  working  on  game  community  development.  Wright  quickly 
moved  the  best  of  that  bunch  in  with  Gamesville.com  and  pulled 
out  Gamesville.com’s  best  database  experts  to  be  part  of  a  central 
database  team.  This  group  now  helps  each  portion  of  the  Lycos  net¬ 
work — from  Angelfire  and  HotBot  to  GuestWorld,  Tripod  and 
Who  Where — set  up,  refine  and  optimize  its  database  resources. 

Wright’s  knack  for  finding  the  best  and  the  brightest  is  a  skill  that 
Lycos  was  looking  for.  “When  Lycos  approached  me  initially,  they 


Lycos  is  discovering  that  letting  acquisitions  live  on 
works  well,  especially  in  the  dotcom  world. 


company  is  built  on  old  technology  and  excising  that  creaky  piece  will 
cause  the  business  to  crumble,  it’s  best  to  steer  clear.  Lycos  particularly 
looks  for  outdated  databases,  software  applications  that  have  been 
too  heavily  customized,  older  operating  systems  and  system  compo¬ 
nents  that  have  a  history  of  not  scaling  well. 

In  its  under-the-hood  inspections,  technology  troubles  caused  Lycos 
to  pull  out  of  two  potential  acquisitions,  Wright  says.  One  of  those 
companies  has  since  gone  out  of  business;  the  other  is  still  independent. 


were  quite  vague  about  what  they  needed,”  Wright  recalls.  “They 
said,  ‘We  know  we  need  help  building  a  reliable,  scalable  infrastruc¬ 
ture,  and  we  don’t  know  how  to  leverage  the  skills  we  have  on  board. 
Can  you  do  that?’  To  accomplish  that,  I’ve  spent  a  lot  of  time  with 
directors,  managers  and  developers  asking  them  about  their  special¬ 
ized  skills.  I’ve  found  that  we  have  within  our  ranks  one  of  the  finest 
collections  of  technical  people  around.” 

Wright  has  also  used  this  technical  skills  collective  to  build  a  central 


136  CIO  JUNE  1,  2000  •  www.cio. com 


sponsored  by  Slj  ERNST  &YOUNG 

From  Thought  to  Finish :m 


S  VS  TE  MS 
MANA  GEM  ENT 


Reboot 

company 


By  Robb  Dongoski 
Ernst  &  Young,  North  American  ESM  Advisory  Leader 


here  used  to  be  a  human  between  your  customer  and  your  IT  systems:  a  thinking  person 
that  could  act  as  a  buffer  and  mask  the  sometimes  chaotic  workings  of  your  organization. 

But  with  e-commerce,  that’s  beginning  to  change.  E-business  cuts  the  human  out  of 
the  equation,  and  allows  your  customer  to  see  right  through  to  the  inner  workings  of 
your  company — good,  bad  and  ugly. 


These  days,  with  dotcoms  and  e-businesses 
all  the  rage,  it’s  tempting  to  concentrate  all 
your  IT  efforts  toward  the  Internet. 

But  now,  while  you’re  trying  to  implement 
those  new  technologies,  is  exactly  the  time 
that  you  should  consider  Enterprise  Systems 
Management  (ESM).  ESM  is  not  just  about 
software  frameworks  and  point  solutions,  it’s 
all  about  the  people,  processes  and  technology 
components  of  IT,  and  how  to  manage  the 
operational  aspects  of  an  IT  environment. 

Today,  many  companies  are  jumping  into 
electronic  business,  as  well  they  should — 


those  who  can’t  adjust  to  the  e-business  model 
are  unlikely  to  survive  very  long.  Most  com¬ 
panies  have  focused  primarily  on  the  techno¬ 
logical  challenges  but  haven’t  looked  closely  at 
the  management  aspects  of  e-business,  the  key 
to  topnotch  performance. 

ESM,  with  its  concentration  on  processes 
and  people — in  addition  to  the  technology — 
can  ensure  that  an  organization's  systems 
deliver  optimum  performance  and  reliability. 
ESM  casts  a  wide  net,  encompassing  issues 
like  performance,  capacity  planning,  opera¬ 
tions,  availability,  customer  management,  and 


security  (see  Figure  1,  page  S2).  It  provides 
the  mechanism  to  effectively  manage  storage, 
applications,  users,  IT  assets,  and  more. 

— ■HfTodau 

»j 

ESM  is  misunderstood  by  many  organizations. 
Users  continue  to  equate  ESM  solely  with  tech¬ 
nology.  As  a  result,  they’ve  often  failed  to  reap  all 
the  benefits  that  ESM  can  provide. 

Most  of  the  time,  implementing  ESM  has 
meant  trying  to  implement  ESM  software  tools. 
The  projects  have  rarely  been  completely  suc¬ 
cessful,  but  the  responsibility  for  this  doesn’t  rest 


Special  Advertising  Supplement 


I J 


ESM  Scope 


Figure  1 


Technology 


The  major  ESM  disciplines,  represented  in  the  figure  above,  are  supported  by  a  solid 
foundation  of  people,  strong  IT  processes  and  enabling  technology. 


solely  with  the  software.  True,  the  tools — often 
complex  and  immature — may  have  failed  to  deliv¬ 
er  as  promised,  but  more  often  than  not,  compa¬ 
nies  failed  to  improve  the  people  and  process  com¬ 
ponents  as  well.  Frequently,  the  results  were 
expensive  disasters. 

For  example,  a  utility  company  recently  pur¬ 
chased  a  costly  ESM  software  package.  The  com¬ 
pany  bought  a  complete  suite  of  software  products, 
assuming  that  they  would  provide  a  stable  frame¬ 
work  on  which  future  projects  could  be  placed. 
However,  the  organization  never  really  analyzed  the 
processes  the  software  was  attempting  to  automate, 
and  never  assigned  a  full-time  team  to  the  effort.  As 
a  result,  they  deployed  less  than  half  the  software 
they’d  bought,  and  never  reached  the  initial  goals 
they’d  set  for  themselves.  This  disappointment  also 
cast  doubt  on  future  IT  initiatives. 

mmidESM 

Even  though  companies  have  had  problems  imple¬ 
menting  ESM  in  the  past,  interest  in  the  discipline 
is  climbing.  Several  forces  are  driving  that  interest: 

>>  Distributed  IT — Most  organizations’  mis¬ 
sion-critical  systems  are  no  longer  neatly 
consolidated  in  one  place.  They’re  spread 
across  the  enterprise,  often  stretching  around 
the  globe.  Organizations  need  to  be  able  to 
effectively  manage  and  coordinate  these  dis¬ 


tributed  environments,  and  ESM  provides 
the  foundation. 

>>  E-business — Company  systems  are  being 
extended  via  the  Internet.  They  now  embrace 
customers,  suppliers,  partners  and  the  public. 
These  widespread  systems  create  a  demand 
for  high  availability,  scalability  and  security. 
ESM  can  help  with  this  demand  by  import¬ 
ing  some  of  the  hard  and  fast  disciplines  from 
the  mainframe  world  to  the  fast  paced  world 
of  e-commerce. 

>  >  High  IT  Costs — Over  the  last  ten  years,  the 

cost  of  IT  has  been  increasing  at  dramatic 
rates.  That’s  no  surprise — IT  is  being  called 
upon  to  take  on  more  and  more  tasks,  and 
trained  IT  workers  are  at  a  premium.  The 
goal  of  IT  departments  should  be  to  do  more 
with  less,  and  get  optimum  leverage  out  of 
every  IT  dollar.  ESM  can  help  by  optimizing 
the  process  behind  the  technology,  and  that 
means  more  bang  for  the  buck. 

>  >  Skills  shortage — As  noted,  trained  IT  work¬ 

ers  are  at  a  premium,  and  the  situation  is  only 
going  to  get  worse.  Meta  Group,  Inc.  says 
that  there  will  be  over  a  million  unfilled  IT 
jobs  worldwide  by  next  year.  Organizations 
can  no  longer  count  on  throwing  more  peo¬ 
ple  at  information  system  challenges — they 
need  to  gain  peak  productivity  from  the  IT 
people  they  already  have,  and  ESM  can  help. 


IT  is  a  key  strategic  component  in  today’s  infor¬ 
mation-based,  Internet-centric  economy.  As  every 
business  rapidly  transforms  into  e-business  to  one 
degree  or  another,  ESM  becomes  the  mechanism 
that  ensures  efficient  operations  and  delivers  the 
level  of  customer  service  needed. 

E  S 0  lb  S 1 3  C 1 0  5 

Interest  is  high,  but  there  are  obstacles  to  achiev¬ 
ing  effective  ESM.  Our  experience  indicates  ESM 
challenges  can  be  overcome.  The  keys  to  success 
include  effective  planning,  a  thorough  under¬ 
standing  of  ESM  complexity  and  a  focus  on  opti¬ 
mizing  core  IT  processes. 

First,  organizations  simply  expect  too  much 
from  the  software  alone.  These  software  tools  are 
often  difficult  to  implement  because  the  needs 
they  address  are  complex.  Over  time,  software  sup¬ 
pliers  and  ESM  customers  have  come  to  recognize 
that  expectations  of  software  have  been  somewhat 
overstated. 

Second,  many  organizations  don’t  have  the 
process  and  organizational  structures  in  place  to 
get  the  most  out  of  the  software  tools  they  do  buy. 
In  the  most  successful  implementations,  ESM 
software  is  accompanied  by  process  reengineering 
efforts. 

For  example,  a  telecommunications  company 
recently  implemented  a  large  ESM  software  frame¬ 
work.  Rather  than  lowering  costs  and  improving 
efficiency,  they’d  achieved  exacdy  the  opposite 
because  the  company  hadn’t  reengineered  its 
processes  along  with  the  software.  The  company 
had,  in  effect,  invested  heavily  to  automate  cumber¬ 
some  processes,  making  the  bad  processes  worse. 
After  analyzing  their  IT  processes,  we  helped  deter¬ 
mine  that  process  reengineering  would  increase 
their  overall  return  by  more  than  1 00  percent. 

Third,  many  organizations  begin  these  efforts 
with  unclear  or  unrealistic  goals.  As  a  result,  the 
scope  of  these  ESM  efforts  is  too  broad  and  unfo¬ 
cused.  Often,  the  efforts  lack  even  a  coherent  start¬ 
ing  point.  No  wonder  they  do  not  reach  their 
expected  returns. 

One  final  reason,  companies  fail  to  align  people 
and  responsibilities.  One  financial  institution,  for 
instance,  spent  $10  million  on  an  ESM  frame-, 
work  without  achieving  any  measurable  benefit — 
there  wasn’t  sufficient  buy-in  at  the  upper  man¬ 
agement  level.  Nobody  with  sufficient  authority 
was  pushing  for  the  success  of  the  project,  or  even 
measuring  the  progress  of  the  effort.  Once  a  prop¬ 
erly  structured  project  team  was  assigned,  with 
the  right  competencies  and  expertise,  the  effort 
took  off. 


S2 


CIO  Special  Advertising  Supplement 


sponsored  by  EjJ ERNST &YOUNG 

From  Thought  to  Finish .  - 


■■■■  I 

Whether  you  realize  it  or  not,  your  organization  is 
practicing  ESM.  Every  company  does,  at  some 
level  or  another.  Whenever  you  perform  backup, 
maintain  a  help  desk,  upgrade  software  or  plan  for 
disaster  recovery,  you’re  practicing  ESM. 

For  most  organizations,  however,  the  ESM 
efforts  are  ad  hoc  and  uncoordinated.  The  results 
are  inefficient,  ineffective,  and  incomplete.  ESM 
becomes  a  series  of  unrelated  activities  and  tasks 
rather  than  well-planned  and  managed  processes. 

We  strive  for  a  balanced  approach  to  ESM. 
While  we  acknowledge  the  importance  of  ESM 
technology,  we  also  focus  on  process  and  people. 
That  means  concentrating  on  methodology, 
reengineering,  personnel  and  organizational  issues, 
not  just  on  software. 

This  balanced  approach — people  and  process  as 
well  as  technology — avoids  many  of  the  problems 
that  have  plagued  ESM  in  the  past. 

An  average  ESM  project  can  be  broken  down 
into  manageable  components  lasting  three  to  five 
months.  We’ve  found  that  each  project  goes 
through  a  five  stage  lifecycle:  Vision,  Aaialyze, 
Design,  Implement  and  Measure  (see  Figure  2). 
There  are  potential  problems  in  each  of  these 
stages,  but  there  are  potential  benefits,  too. 
Through  all  five  stages,  strong  executive  sponsor¬ 
ship,  focused  project  direction  and  the  involve¬ 
ment  of  users  are  vital  to  the  success  of  the  project. 

The  ideal  way  to  begin  an  ESM  project  is  to 
start  at  the  vision  stage.  However,  some  companies 
may  already  be  in  the  midst  of  an  ESM  project. 
Regardless  of  the  ESM  lifecycle  stage  you  are  in, 
Ernst  &  Young’s  experience  indicates  significant 
benefits  can  be  obtained  from  re-assessing  where 
you  are  in  the  lifecycle  and  determining  the  next 
best  steps. 

Using  this  approach,  we  help  organizations 
identify  the  stages  with  the  highest  value  areas,  and 
then  set  the  priorities  for  the  project.  By  focusing 
on  the  high  value  areas  first,  you  see  a  payback 
early,  and  that  payback  can  be  used  to  fund  the 
future  stages  of  the  project. 

High  payback  areas  typically  include  user  and 
security  administration,  asset  management  (hard¬ 
ware  and  software  lifecycle  management  from 
acquisition  through  disposal),  and  customer  service 
management  including  help  desk.  One  global  bank 
we  worked  with  generated  $135  million  in  savings 
over  four  years  through  focused  ESM  initiatives. 


is  ESM 

When  done  correctly,  ESM  certainly  produces 
attractive  savings.  Most  of  our  clients  achieve  a  50 

CIO  Special  Advertising  Supplement  _ 


to  over  200  percent  return  on  their  ESM  invest¬ 
ment,  but  there’s  more  to  ESM.  It  allows  managers 
to  effectively  manage  their  organization's  systems 
as  a  valuable  resource. 

With  ESM,  managers  can  run  systems  the  way 
they  run  the  rest  of  the  business — with  a  clear  view 
of  the  underlying  process.  From  an  enterprise- 
wide  perspective,  managers  can  drill  down  to 
examine  specific  problems,  and  new  applications 
or  systems  can  be  introduced  without  increasing 


IT  costs  or  personnel — In  short,  ESM  provides 
the  foundation  to  support  business  growth.  ill 

For  further  information  contact  Robb  Dongoski: 


robert.dongoski@ey.com 


Or  visit  our  Web  site: 


ey.com/esm 


ESM  Lifecycle 

Stage  Stage  Characteristics 

1 

Figure  2 

Recommended  Next  Steps 

Vision 

>> 

Fragmented  IT  processes 

>> 

Establish  project  executive 

>> 

Some  ESM  disciplines  have 

sponsorship 

been  addressed  in  pockets 

>  > 

Identify  key  stakeholders 

throughout  the  organization 

>> 

Execute  diagnostic  to  define 

>  > 

Enterprise  wide  focus  has  not 

primary  ESM  improvement 

been  established 

objectives 

Analyze 

>  > 

Sponsorship  and  stakeholders 

>  > 

1 

Establish  specific  technical  and 

are  in  place 

functional  requirements 

>  > 

Objectives  have  been 

>  > 

Develop  high-level  future  state 

established 

ESM  architecture 

>  > 

IT  processes  are  not  well 

>  > 

Evaluate  available  and  existing 

defined 

ESM  software  capabilities 

>> 

ESM  technology  tools  need 

to  be  evaluated 

Design 

>  > 

A  comprehensive  plan  is  devel- 

>  > 

Develop  a  focused,  core 

oped  to  achieve  future  state 

project  team 

ESM  architecture 

>  > 

Develop  a  solution  prototype 

>  > 

Users  have  not  been  adequate- 

>  > 

Define  and  document  future 

ly  trained 

state  processes 

>  > 

ESM  software  tools  have  not 

>  > 

Develop  a  phased  development 

been  implemented  yet 

and  implementation  plan 

>> 

Engage  users  during  prototype 

development  and  testing — their 

input  is  vital,  it  makes  them  an 

integral  part  of  the  process. 

Implement 

>> 

Implementation  of  software 

>  > 

Execute  your  implementation 

technology  is  under  way 

plan 

>  > 

IT  processes  have  not  been 

>> 

Manage  organizational 

completely  reengineered 

changes  to  mitigate  project  risk 

>  > 

Organizational  changes  are 

>> 

Over-communicate  project 

needed  in  order  to  be  effective 

success;  "market  your  wins" 

>> 

Executive  sponsorship  is  critical 

>  > 

Refine  process  design  j 

>  > 

Users  need  training  of  both 

documentation 

processes  and  technology 

>> 

Document  functional 

responsibilities 

Measure 

>  > 

Performance  metrics  are  not 

>  > 

Define  key  performance 

readily  available 

indicators  based  on  customer 

>> 

Tools  and  processes  may  not  be 

expectations 

in  place  to  provide  meaningful 

>  > 

Define  ESM  measurement 

performance  information 

processes 

>> 

Performance  metrics  are  not 

>  > 

Compare  "current  state"  versus 

aligned  with  customer 

desired  "future  state" 

expectations 

S3 


Connectivity  has  stepped  up  the  pace  of  change 
in  the  business  world.  Change  happens  best  when  our 
ability  to  share  information  is  at  its  smoothest.  Information 
flows  best  when  connections  are  seamless.  Our  knowledge  of 
e-commerce  and  the  impact  technology  can  have  on  your  business 
can  help  you  make  it  all  possible.  Let’s  come  together,  ey.com/esm 


Ernst  Young 


©2000  Ernst  &  Young  up 


'ctober  15-18,  2000 


lizona  Bilim  ore 

|  j: 

hoenix,  Arizona 


|  B 

X  v‘x  .  .  ^ 

•V. ' 

11' 

IkJx 

B  ■.>•. 

*  Iuk 

][i| 

W  *  I  [1 

Tijk 

tfi] 

4  il»] 

W0  1 

1  B  1 

J  m 

v  ’  /--B 

•-:  1 

K&gfli 

VmKB0 

. .,  'BMBr' 

Mergers  &  Acquisitions 


Shopping  Basket 

Lycos  has  been  on  a  buying  spree,  spending  nearly  $685  million  on  acquisitions  since  February  1998.  Its  haul  includes  the  following: 


February  2000 

Valent  Software 

Developer  of  community-building  software 

$45  million 

November  1999 

Gamesville.com 

Games  website 

$207  million 

September  1999 

Quote.com 

Financial  services  website 

$78.3  million 

August  1999 

Internet  Music  Distribution  Inc. 

Developer  of  Sonique  PC  audio  player 

$37  million 

October  1998 

Wired  Digital  Inc. 

Developer  of  HotBot,  Wired  News  and  Suck.com 

$83  million 

August  1998 

WhoWhere 

Online  directory,  e-mail  and  homepage  building 

$133  million 

August  1998 

GuestWorld 

Developer  of  online  guest-book  services 

$3.9  million 

April  1998 

WiseWire  Corp. 

Developer  of  customized  and  personalized  search  tools 

$39.8  million 

February  1998 

Tripod  Inc. 

Online  community  developer 

$58  million 

architecture  team  that  advises  him  about  new  and  innovative 
technologies.  (See  “The  Future  of  Technology  Starts  Here,”  Page  134.) 
“This  group  is  charged  with  finding  technology  that  will  help  us  deliver 
more  and  larger  content  faster  and  more  reliably,”  Wright  says. 

Not  So  Fast 

Tom  Nolle,  president  of  CIMI  Corp.,  a  Voorhees,  N.J.-based  con¬ 
sultancy,  says  Lycos  will  be  challenged  to  lay  out  an  infrastructure 
to  fit  its  business  model  because  “a  large  business  model  requires 
focus  and  planning  far  ahead,  which  is  almost  contrary  to  what’s  hap¬ 
pening  on  the  internet.”  Wright  responds  that  Lycos  doesn’t  have  a 
traditional  slow-moving  corporate  culture.  “When  we  identify  a  need, 
we  move  very  quickly,”  he  says.  Wright  explains  that  he  is  planning 
for  future  network  needs  by  centralizing  basic  network  functions. 
At  the  same  time,  Lycos  allows  divisions  to  stay  flexible  and  respon¬ 
sive  by  letting  them  focus  their  attention  and  expertise  on  their  core 
products  and  their  competition.  If  they  see  something  that  needs  to 
change,  they  can  quickly  adjust  it  because  they  don’t  have  to  cut 
through  layers  of  corporate  tape. 

Not  everything  Wright  has  tried  has  worked.  “I  thought  I  could 
centralize  customer  service  because  that  worked  well  at  The 
Learning  Co.,  but  it  didn’t  work  here,”  he  says.  “Customer  service 
is  product-centered,  and  the  type  of  specialized  support  required 
for  a  financial  site  such  as  Quote.com  is  completely  different  from 
the  support  Gamesville.com  needs.”  Lycos  had  even  scouted  loca¬ 
tions  for  a  centralized  service  center  but  hadn’t  yet  begun  to  evalu¬ 
ate  technologies  when  Wright  scrapped  the  idea  after  an  early  look 
a  potential  staffing  costs. 

Lycos  is  still  also  working  out  the  kinks  in  its  universal  registra¬ 
tion  process.  In  order  to  make  personalized  Lycos  Network  services 


such  as  MyLycos  or  Quote.com  useful,  each  site  requires  informa¬ 
tion  about  the  visitor.  Wright  and  his  developers  are  attempting  to 
fold  as  much  of  that  registration  process  into  one  form  without  slow¬ 
ing  down  site  performance.  “It’s  a  complex  balance.  We’re  building 
a  robust  system  to  handle  up  to  1  million  registrations  a  day,  while 
keeping  in  mind  that  we  don’t  want  to  affect  an  individual  site,” 
Wright  explains. 

Even  with  these  small  stumbles,  Wall  Street  observers  think  Lycos 
has  approached  the  acquisition  process  very  well.  “It  was  one  of  the 
early  leaders  in  acquiring  [internet]  market  share  through  strategic 
acquisitions  at  good  prices,”  says  Andrea  Williams  Rice,  managing 
director  of  internet  research  at  Deutsche  Banc  Alex-Brown  in  San 
Francisco.  “Wall  Street’s  perception  of  Lycos  has  changed  because 
of  how  smart  it  has  been  in  making  acquisitions  and  how  well  it  has 
integrated  them.  It’s  pretty  impressive  to  see  Lycos  take  on  so  many 
acquisitions  and  still  be  one  of  the  few  internet-based  companies  that’s 
turning  a  profit.” 

Wright  and  Lycos  feel  that  they’ve  found  the  right  way  to  bring 
in  acquisitions  under  their  corporate  umbrella,  nurture  and  feed  them, 
and  turn  them  into  productive  and  profitable  scions.  They  give  them 
room  to  grow  by  pruning  off  and  centralizing  some  of  the  basic  every¬ 
day  administrative  and  network  functions,  but  Wright  knows  that  too 
much  heavy-handed  oversight  will  crush  entrepreneurial  spirit. 

“My  job  is  to  help  Lycos  deliver  content  faster;  cheaper  and  better;” 
he  says.  “So  far;  by  combining  our  resources  the  right  way  and  using 
the  staff  to  its  best  advantage,  I  think  we’re  doing  just  that.”  BE] 


Stewart  Deck  didn't  win  Gamesville.com's  NCAA  basketball  pool,  but  he’s  still 
alive  in  the  backgammon  tournament.  Bring  him  back  to  reality  by  sending  an 
e-mail  to  sdeck@cio.com. 


138  CIO  JUNE  1,  2000  •  www.cio.com 


the  new  ThinkPad  A20p 

From  presentations  to  movie  editing,  the  ThinkPad  A20p  is  a  perfect  multimedia  tool.  It's  fast.  It's  powerful. 

It  comes  with  video  in/out,  loads  of  vram,  and  a  huge  viewing  screen.  And  it’s  so  easy,  you’ll  actually  use  it 
all.  Multimedia  simplified.  Just  one  more  example  of  the  ThinkPad  experience.  But  watch  out:  this  notebook 
has  not  yet  been  rated.  To  order  call  800  426  7255  or  visit  ibm.com 

Intel’  Pentium’  III  processor  700mhz7128mb  sdram  /18gb2  hdd  /  dvd  / 15"  TFT  screen  /  $3899  (©business  tools 


IT’S  A  COMPUTER. 

BUT  WHAT  IT  REALLY  WANTS  TO  DO  IS  DIRECT 


'mhz  only  measures  microprocessor  internal  clock  speed;  many  factors  affect  application  performance.  Jgb  equals  one  billion  bytes  when  referring  to  storage  capacity;  accessible 
capacity  may  be  less.  ’Estimated  reseller  price  for  model  2629-61 U.  Actual  prices  may  vary.  PCs  referred  to  in  this  ad  include  an  operating  system.  IBM  product  names  are 
trademarks  of  International  Business  Machines  Corp.  Intel,  the  Intel  Inside  logo  and  Pentium  are  registered  trademarks  of  Intel  Corporation.  ©  2000  IBM  Corp.  All  rights  reserved. 


PHOTO  BY  JOHN  RAE 


Asset  Management 


Keeping  tabs  on  all  your  IT  assets  may  seem  nearly  impossible s 

but  a  formal  approach  and  the  right  systems  can  make  it  pay 


For  many  years,  American  Home  Products 

Corp.  managed  its  IT  assets  in  a  helter-skelter  fashion,  like 
many  other  large  organizations  at  the  end  of  the  20th  century. 
Each  of  the  sites  in  the  Madison,  N.J.-based  company’s  phar¬ 
maceutical  division  managed  its  own  hardware  and  software 
using  a  different  spreadsheet  or  database,  or  manual  list  of 
assets.  Derek  Bluestone,  the  division’s  senior  manager  for  global 
IT  sourcing  and  acquisitions,  admits  the  process  was  inconsis¬ 
tent  and  company  executives  had  little  idea  what  assets  the  divi¬ 
sion  had,  what  they  cost,  how  those  assets  were  being  used 
and  even  why  they  had  been  purchased  in  the  first  place. 
What’s  more,  the  division  was  beset  by  duplication  of  effort  in 
PC  procurement  and  management,  multiple  software  and 
hardware  surveys  undertaken  by  different  departments,  and 
incomplete  and  inconsistent  information  across  the  board. 

And  that’s  not  the  half  of  it.  Company  analysts  weren't 
able  to  adequately  track  whether  vendors  were  submitting 
invoices  for  software  maintenance  that  adhered  to  contractual 


caps.  And  financial  analysts  found  it  impossible  to  match  up 
the  return  of  leased  equipment  to  schedules  or  compare  quar¬ 
terly  invoices  with  the  proper  cost  formulations. 

“We  finally  realized  that  not  knowing  what  we  had  was  cost¬ 
ing  us  a  lot  of  money,”  says  Bluestone.  For  example,  desktop 
and  notebook  inventories  were  gathered  several  times  each 
year  but  were  stored  in  inconsistent  formats  ranging  from 
spreadsheets  to  Microsoft  Access  databases.  Sometimes  the 
division  paid  outside  vendors  to 
take  inventor)’;  other  times  it 
had  to  allocate  internal  re¬ 
sources.  And  because  most  of 
the  division’s  notebook  comput¬ 
ers  are  leased,  Bluestone  adds, 

“we  were  actively  looking  to 
reduce  the  payment  of  interim 
rents  for  older  equipment  after 
the  leases  expired.” 


Reader  ROI 

►  Discover  the  hidden  costs 
and  savings  in  comprehen¬ 
sive  asset  management 

►  See  expert-recommended 
steps  to  take 

►  Find  out  what  asset  man¬ 
agement  practitioners  have 
learned 


www.cio.com 


JUNE  1.  2000  CIO  14  1 


Asset  Management 


After  surveying  the  situation,  the  division  estimated  it  was 
spending  $250,000  annually  in  hard  costs — much  of  which 
Bluestone  and  his  team  believed  could  be  eliminated  by  adopting 
a  formal  asset  management  approach. 

The  $14  billion  global  pharmaceutical  and  consumer  health¬ 
care  products  company  has  since  embarked  on  a  multiyear  cam¬ 
paign  to  gain  control  of  its  sprawling  IT  assets,  which  include  as 
many  as  30,000  PCs  and  a  slew  of  other  IT  equipment  and  soft¬ 
ware  scattered  around  the  world.  Besides  saving  considerably  in 
hard  costs,  the  new  approach  should  substantially  cut  network 
infrastructure  maintenance  expenses.  In  Bluestone’s  division,  for 
example,  his  team  can  now  use  asset  management  reconciliation 
processes  and  tools  to  identify  and  retire  equipment  no  longer  in 
use.  On  one  annual  contract  alone,  that  saved  $150,000.  Formal 
asset  management  will  be  a  tough  job  for  American  Home 
Products — but  Bluestone  is  convinced  it  will  pay  off  big. 


Controlling  Your  Environment 

More  and  more  companies  are  finding  that  their  IT  environ¬ 
ments  are  getting  out  of  control  and  are  opting  for  a  formal, 
comprehensive  asset  management  strategy  that  not  only  tracks 
hardware  and  software  assets,  but  also  manages  software 
licenses,  equipment  contracts  and  leases,  and  networks  from  cra¬ 
dle  to  grave.  The  goal  for  many  companies  is  to  start  manag¬ 
ing  an  asset  even  before  it  is  purchased,  keep  tabs  on  it  during 
procurement  and  follow  it  through  the  loading  dock,  installa¬ 
tion,  loading  and  managing  software  on  the  asset,  and  right 
through  to  recycling. 

Although  it  is  common  for  companies  to  implement  certain 
asset  management  practices  on  their  own — such  as  centralized 
procurement  and  standardization  on  a  number  of  supported  con¬ 
figurations — it  would  be  quite  difficult  for  them  to  implement  a 
strategy  encompassing  IT,  finance,  facilities  and  suppliers 


Nonstandard  Issue 


Managing  wireless  devices  often  consists  of  simply  knowing  they’re  falling  through  the  cracks 


Businesspeople  rarely  leave  their  desks 
without  some  variety  of  wireless  equip¬ 
ment-notebook  computers,  cell  phones, 
personal  digital  assistants  and  pagers  are 
the  accessories  du  jour.  The  increasing  use 
of  these  devices  presents  a  nettlesome  chal¬ 
lenge  for  companies  looking  to  track  assets. 
By  their  very  nature,  these  devices  don’t 
stay  in  one  place  for  long  and  are  off  the 
corporate  intranet  much  of  the  time,  making 
them  difficult— if  not  impossible— to  track. 
Centralized  administration  is  the  heart  of 
asset  management,  and  “wireless  devices 
spend  a  lot  of  time  sitting  in  someone’s 
back  pocket,”  says  Kevin  Burden,  a  senior 
analyst  in  the  asset  management  services 
division  of  IDC  in  Framingham,  Mass. 
“There  is  simply  no  way  to  poll  the  net¬ 
work  and  find  out  how  many  handheld 
devices  you  have  out  there.” 

Wireless  devices  are  also  difficult  to 
manage  because  they  are  so  portable. 

“Joe  might  leave  the  company  on  the 
same  day  that  Mary  joined,  so  somebody 
has  the  great  idea  to  give  Joe’s  laptop  to 
Mary.  All  of  a  sudden,  a  unit  manager 


realizes  she  is  being  charged  for  Joe’s 
laptop  when  Mary  is  in  a  different  divi¬ 
sion,”  explains  Sue  Ben,  formerly  director 
of  distributed  technology  and  now  business- 
to-business  IT  director  at  Sears,  Roebuck 
and  Co.  in  Hoffman  Estates,  III. 

But  IT  managers  don’t  seem  particu¬ 
larly  worried  about  tracking  these  devices. 
First  thing's  first,  they  reason— and  that 
means  having  good,  centralized  control  of 
expensive  IT  assets  before  even  consider¬ 
ing  tracking  mobile  devices.  “We  plan  to 
eventually  manage  wireless  devices  with 
the  same  tools  we  are  using  for  other  IT 
assets,  but  it’s  last  on  the  list,”  Ben  says. 
Ideally,  the  company  would  like  to  imple¬ 
ment  a  web-based  system  that  will  allow 
employees  to  manage  and  track  mobile 
devices  in  a  self-service  manner. 

Derek  Bluestone,  senior  manager  for 
global  IT  sourcing  and  acquisitions  at 
Madison,  N.J.-based  American  Home 
Products  Corp.,  says  quick  usage  cycles— 
as  fast  as  six  to  eight  months— make  the 
units  particularly  frustrating  to  track.  So 
the  company  has  decided  to  focus  its  new 


asset  management  system  on  the  bigger 
ticket  items  first.  “As  our  strategy  around 
nonstandard  devices  becomes  more 
mature  and  as  the  market  becomes  more 
mature,  we’ll  see  whether  it  makes  sense 
to  track  those  devices,”  he  says.  “But  for 
now,  we’re  not  using  the  system  to  track 
them  at  all." 

Although  it's  at  the  bottom  of  corporate 
to-do  lists  now,  tracking  wireless  units  will 
become  more  important  over  time.  “Even 
though  the  majority  of  IT  departments 
haven't  yet  committed  a  formalized  support 
program  for  them,  you  know  help  desks  are 
getting  calls,”  Burden  says.  “What  will 
probably  happen  is  that  companies  will 
realize  how  much  time  users  are  spending 
supporting  themselves  and  their  neighbors. 
Eventually,  they  will  direct  the  IT  depart¬ 
ment  to  develop  support  policies.” 

The  only  way  IT  departments  will  be 
able  to  deliver  support  efficiently,  Burden 
says,  is  to  mandate  the  procurement  of  a 
small  subset  of  handheld  devices  so  they 
can  be  as  familiar  as  possible  with  the 
devices  they  are  supporting.  -K.  Schwartz 


142  CIO  JUNE  1,  2000  •  www.cio.com 


Almost 
a  secure 
enterprise. 

Your  data  network  is  only  as  secure  as  your 
telephone  network. 


Introducing  the  TeleWall™  security  solution, 


the  first  telephone  firewall  system  that  works  alongside  the 
data  network  security  system  to  fully  protect  your  enterprise. 
The  simple  act  of  connecting  a  modem  provides  a  direct  “back 
door”  link  between  the  public  phone  system  and  your  data 
network.  The  TeleWall  solution  allows  you  to  shut  down 
rogue  modems,  block  would-be  intruders  and  police 
unauthorized  traffic  via  centralized  management  of  a  fully 
distributed  sensor  system.  And  with  enterprise-wide  visibility, 
you  get  real-time  data  on  the  use  of  your  telephone  system, 
and  analytical  data  to  calculate  financial  return-on-investment. 

So  unless  you  have  an  “open  door”  policy  for  your  data  network, 
it’s  time  you  hatched  a  new  plan  for  enterprise  security. 

Go  to  www.securelogix.com/egg 


4^  SecureLogix 

CORPORATION 

rffl 

Protecting  Data  Networks  by  Securing  Telephone  Networks 
Call:  800-817-4837  Email:  sales@securelogix.com 

TeleWall,  SecureLogix  and  the  SecureLogix  logo  are  trademarks  ot  SecureLogix  Corporation, 
©  Copyright  2000  SecureLogix  Corporation. 


Asset  Management 


without  using  packaged  applications,  says  Kevin  Burden,  a  senior  ana¬ 
lyst  in  the  asset  management  services  division  at  IDC,  a  Framingham, 
Mass.-based  FT  consultancy  and  sister  company  to  CIO. 

If  it  is  done  right,  implementing  a  formal  asset  management  strat¬ 
egy  can  really  cause  savings  to  mount,  especially  when  measuring 
total  cost  of  ownership  (TCO),  Burden  says.  For  example,  at  a  1,000- 
user  site,  the  average  annual  staffing  cost  per  PC  is  $5,236.  When  IDC 
looked  at  data  from  sites  that  don’t  practice  asset  management,  that 
number  jumped  to  $5,593.  Sites  that  practiced  asset  management 
were  able  to  cut  their  costs  to  an  average  of  $4,880 — 15  percent 
lower  than  the  nonpractitioners. 

Cutting  costs  is  exactly  what  Sears,  Roebuck  and  Co.  of  Hoffman 
Estates,  Ill.,  had  in  mind  when  it  decided  in  late  1997  to  install  an 
asset  management  system.  The  company  manages  more  than  300,000 
pieces  of  hardware  used  by  more  than  320,000  employees  in  the 
United  States.  The  move  away  from  green-screen  terminals  in  the 
1990s  and  then  the  need  to  account  for  each  and  every  piece  of  soft¬ 
ware  and  hardware  in  preparation  for  Y2K  precipitated  Sears’  devel¬ 
opment  of  a  comprehensive  asset  management  strategy. 

Once  the  company  began  switching  employ¬ 
ees  from  the  green-screen  environment,  its 
PC  inventory  snowballed — Sears  has  de¬ 
ployed  about  45,000  PCs  within  the  past 
few  years.  The  company  also  began  shift¬ 
ing  from  mainframe  systems  to  client/ 
server-based  systems,  and  the  number  of  IT 
assets  skyrocketed.  But  above  all,  the  impetus 
was  time.  “Y2K  was  a  real  eye-opener  because 
it  was  the  first  time  we  had  to  determine  what 
we  had  and  what  it  was  capable  of,” 
says  Sue  Ben,  former  director  of  dis¬ 
tributed  technology  and  now  Sears’ 
business-to-business  IT  director.  “It 


Sue  Ben,  business-to-business  IT 
director  for  Sears,  credits  Y2K 
remediation  with  unearthing  all 
of  Sears’  assets  and  extending 
their  longevity. 


forced  us  to  have  to  know  the  longevity  of  each  asset,  whether  the 
asset  was  currently  in  use,  if  it  could- be  reused,  if  we  could  protect 
the  asset  and  how  we  could  manage  the  asset.” 

It  was  in  1997,  too,  that  American  Home  Products  executives 
had  finally  had  enough  and  resolved  that  out-of-control  inventories 
and  wasted  money  didn’t  have  to  be  a  fact  of  life.  Slowly,  they  began 
to  realize  that  enterprise  asset  management  was  a  core  IT  discipline — 
alongside  problem  management,  change  management,  service  request 
management  and  service-level  management.  What  the  pharmaceuti¬ 
cal  division  needed,  they  decided,  was  a  comprehensive  system  to 
track  hardware  and  software  assets,  as  well  as  software  licensing 
agreements  and  equipment  leases.  Its  12-member  Global  IT  Sourcing 
group  chose  a  comprehensive  approach  because  of  the  complexity 
of  the  cost  trail  and  relationship  trail  of  IT  assets,  which  included 
the  initial  purchase  cost,  the  department  or  project  budget  that  paid 
for  it,  recurring  maintenance  costs,  related  costs  from  software  and 
service,  the  cost  of  administering  and  maintaining  the  asset,  and 
upgrade  and  add-on  costs. 

Bluestone  explains,  “I  may  have  a  mainframe  with  50  or  more 
software  licenses  on  it,  and  each  one  of  those  licenses  has  a  mainte¬ 
nance  stream.  And  for  the  mainframe  hardware,  there’s  a  maintenance 
contract  and  cost  stream.  There  are  contracts  for  each  one  of  those 
licenses  with  specific  terms  and  conditions  that  need  to  be  man¬ 
aged  and  adhered  to.”  By  early  1998,  the  team  had  chosen  Argis, 
from  Pittsburgh-based  Janus  Technologies,  which  it  uses  in  con¬ 
junction  with  Tebanon,  N.H. -based  Tally  Systems’ 
NetCensus  to  manage  its  IT  assets.  Argis  allows  the 
division  to  link  software  asset  records  to  legal  docu¬ 
ment  and  hardware  asset  records.  “Effectively,  we 
are  able  to  look  up  a  server  to  see  what  software 
is  running,  maintenance  renewal  dates  and 
maintenance  caps,  and  the  specific  grant  of  use 
of  the  license,”  Bluestone  says. 

A  different  situation  inspired  Williams 
Communications  Group  to  implement  an  asset 
management  system.  The  Tulsa,  Okla.-based 
provider  of  carrier  network  products  and  services 
was  launched  by  its  parent,  The  Williams 
Companies,  about  two  years  ago  and  has 
9,000  employees  in  150  offices  around  the 
world.  “We’ve  seen  our  assets  grow  incred¬ 
ibly  quickly  and  dynamically,”  says  Randy 
Tucker,  the  company’s  vice  president  of 
infrastructure.  “An  asset  might  be  on  one 
desktop  today  and  another  one  tomor¬ 
row,  and  configured  one  way  today 
and  another  way  tomorrow.”  After 
consulting  with  Gartner  Group  on 
the  most  appropriate  system  for  its 
needs  and  conducting  its  own 


PHOTO  BY  GREG  GILUS 


I 

I 


http-. //www.  aa.com 


Yl 


-T  E ' : 


•TEC 


-?  ■  ■ 


X 


Make  sure  your  site  takes  c#,  too. 

When  it  came  time  for  American  Airlines  to  expand  the  capacity  of  aa.com,  how 
did  they  get  a  site  that  big  off  the  ground?  They  chose  e-TEST™  suite  from  RSW 
Software.  Not  only  did  e-TEST™  verify  site  functionality  and  load  capacity,  but  the 
support  team  from  RSW  Software  helped  with  everything  from  network  architectures 
and  Internet  systems,  to  performance  criteria  and  firewall  configurations.  And  it  all  came 
in  right  on  schedule.  Now,  because  of  e-TEST,  the  aa.com  site  is  flying  high. 


Download  a  fully  functional  version  of  e-TEST  suite  for  free  -  and  start  testing  your  site  in  minutes. 
Plus,  get  the  free  white  paper  "Making  e-Business  Work"  by  the  Newport  Group,  with  information  on 
how  to  avoid  scalability  problems.  Visit  www.e-TESTED.com  or  call  781-993-8500. 


download  <  e-TEST  suite  >  today! 

- - 1 

visit. 

<e-TESTED.com> 

RSSA/software 


e-TEST ™  for  e-Business  e-TEST  is  a  trademark  of  RSW  Software,  Inc.  -  A  Teradyne  Company  •  www.rswsoftware.com  •  781-993-8500 

AA  and  aa.com  are  registered  trademarks  of  American  Airlines. 


Asset  Management 


evaluation,  the  company  chose  AssetCenter  from  Peregrine 
Systems  of  San  Diego  because  it  met  its  primary  criteria  of  ease 
of  use  and  robust  functionality. 

“We  have  about  one-third  of  our  PCs  coming  off  lease  this 
year,  and  one  of  our  business  units  has  added  about  2,000  PCs. 
That  constitutes  a  pretty  big  chunk  of  our  asset  base,”  Tucker 
says.  “That,  combined  with  the  expected  growth  we  have  going 
forward,  made  us  recognize  that  using  Excel  spreadsheets  to 
manage  our  assets  just  wasn’t  going  to  cut  it  anymore.” 

Step-by-Step 

Before  an  organization  looks  for  an  asset  management  package, 
experts  recommend  taking  several  steps.  The  first,  Burden  says,  is 
understanding  the  businesses  that  the  IT  department  serves,  along 
with  those  business  units’  goals  and  objectives. 

The  next  step  is  identifying  current  technologies  serving  the 
business.  By  using  the  type  of  system  management  tools  most 


Asset  management  has  meant  consistency  and 
purchasing  power  for  Marriott  International  franchises 
around  the  globe,  says  CIO  Carl  Wilson. 


organizations  already  have  in  place — such  as  Microsoft’s 
Systems  Management  Server  (SMS),  Hewlett-Packard’s  HP 
Open  View,  Computer  Associates’  CA-Unicenter,  Tally  Systems’ 
NetCensus  or  one  of  several  tools  from  Tivoli  Systems — com¬ 
panies  can  accurately  count  physical  IT  assets,  including  the  ver¬ 
sion  of  each  software  package  installed  on  a  hardware  asset. 

Like  any  other  big  project,  it  is  critical  to  obtain  buy-in  from 
upper  management  and  the  rest  of  the  organization  before  pro¬ 
ceeding  to  a  more  comprehensive  undertaking,  or  the  project 
is  likely  to  fail.  “We’ve  been  actively  involved  in  asset  manage¬ 
ment  now  for  almost  two  years,  and  one  of  the  biggest  lessons 
we’ve  learned  is  that  support  from  senior  management  to  imple¬ 
ment  and  monitor  the  program  is  a  must,”  says  Carl  Wilson, 
CIO  of  Bethesda,  Md. -based  Marriott  International.  “Indi¬ 
vidual  users  have  peripheral  vision  on  what  they  want  to 
accomplish,  but  somebody  with  overall  accountability  for  long¬ 
term  costs  and  strategy  can  really  understand  the  value  of  hav¬ 
ing  effective  management  of  IT  assets.  For  us,  it’s  been  a  top- 
down  directive  to  proceed  with  asset  management;  without 
that,  we  wouldn’t  be  as  successful  as  we  are.” 

Given  the  go-ahead,  the  team  should  then  determine  crite¬ 
ria  for  choosing  a  system  based  on  the  function  it  wants  the 
system  to  provide  to  the  company  or  the  business  unit. 
Sometimes,  managing  software  licenses  is  the  prime  mover; 
other  times,  it’s  a  dire  need  to  track  leases.  Sears  took  about 
six  months  to  develop  a  strategy  and  another  three  months 
to  search  for  appropriate  products.  During  that  time,  the  asset 
management  group  systematically  looked  at  what  it  would 
take  to  bring  together  financial  management  with  recording 
and  procurement  of  assets,  lease  terms  and  software  licens¬ 
ing  terms.  Complicating  the  selection  process,  the  chosen 
tool  would  have  to  interface  with  the  company’s  custom- 
developed  accounting  system,  a  PeopleSoft  HR  system,  a 
facilities  management  system  and  a  contractor  badge 
management  system.  Sears  finally  chose  a  system  from 
MainControl  of  McLean,  Va.,  that  also  works  in  concert  with 
Tally  Systems’  NetCensus,  which  Sears  was  already  using,  as 
well  as  with  Microsoft’s  SMS,  a  component  added  later. 

At  Marriott,  executives  watched  for  years  as  property  own¬ 
ers  and  franchisees  bought  hardware  from  no-name  manufac¬ 
turers  with  depreciation  or  amortization  cycles  of  up  to  five 
years,  when  two  or  three  years  might  have  been  more  appro¬ 
priate.  “We  found  that  individual  owners  wanted  to  depreciate 
PCs  over  a  longer  period  of  time  than  their  effective  use,  but 
doing  that  with  the  relative  cost  of  technology  coming  down, 
they  may  end  up  having  an  asset  on  their  books  that  has  a 
higher  book  value  than  its  true  market  usage  value,”  Wilson 
says.  Using  asset  management  and  establishing  relationships 
with  major  PC  providers  around  the  world,  “we  can  remove 
that  problem  from  our  franchisees  and  owners,  because  they  can 


146  CIO  JUNE  1.  2000  •  www.cio.com 


PHOTO  COURTESY  OF  MARRIOTT  INTERNATIONAL 


Nasdaq:  CHRP 


Now,  everything  is  possible. 

Local  is  global. 


And  open  is  secure. 


-  - .  ■ 


Whatever  else  the 
Internet  has  done,  it's  shrunk  the 
world  considerably.  Anyone,  anywhere, 
can  purchase  virtually  anything  online.  But  for 
your  e-business  to  succeed,  your  customers  need 
to  rest  assured  their  data  will  safely  get  where  it's  going. 
And  nowhere  else.  That’s  why  Check  Point’s  Secure 
Virtual  Network  incorporates  not  only  the  best  VPN 
technology,  but  all  the  critical  elements  necessary  for  a 
secure  Internet  environment.  Our  SVN  architecture  forms 
a  comprehensive  layer  that’s  fully  aware,  not  just  of 
your  extended  network,  but  of  even’  user,  system 
and  application  on  it.  Which,  in  turn,  explains 
why  we  have  more  security  installations  than 
anyone  else  in  the  world.  To  feel  more 
secure  immediately,  check  out 
ww w.checkpoint  .com  today. 


Checkpoint 

Software  lechnologies  Ltd 


©  2000  Check  Point  Software  Technologies  Ltd. 


We  Secure  the  Internet. 


i 


Asset  Management 


now  get  the  technology  when  they  need  it  by  doing  an  opera¬ 
tional  lease  and  leveraging  Marriott’s  total  procurement  power. 
That  way,  our  owners  and  franchisees  could  project  a  consis¬ 
tent  cost,  and  total  cost  of  ownership  would  decrease.” 

Another  strategic  concern  shaping  Marriott’s  criteria  for 
selecting  a  vendor  was  the  treatment  of  software  licenses.  “You 
want  to  protect  against  pirated  copies  and  make  sure  you  have 
the  most  current  version.  Our  people  out  in  remote  locations 
may  not  be  aware  that  software  they  are  picking  up  may  be 
pirated.  We  needed  a  central  way  to  control  that  so  we  can  make 
sure  Marriott  honors  its  commitments  to  all  of  its  suppliers,” 
Wilson  notes.  “And  by  being  able  to  explore  what  is  on  the 
network,  we  can  see  what  equipment  and  capacity  everyone  has, 
which  can  help  us  get  ready  to  do  a  major  software  upgrade, 
while  also  helping  us  better  control  our  capital  expenditures.” 
Marriott  now  uses  Asset  Insight  from  Cary,  N.C. -based 
Tangram  Enterprise  Solutions  in  concert  with  tools  from  Tivoli 
Systems  to  manage  its  IT  assets. 

By  employing  an  asset  management  strategy,  a  company 
can  avoid  letting  vendors  dictate  what  to  upgrade.  “Without 
asset  management,  companies  might  end  up  buying  the  prod¬ 
ucts  and  technologies  that  are  showing  the  best  profit  for  the 
vendor  instead  of  the  technologies  they  really  need.  And  there 
is  a  real  savings  in  knowing  exactly  what  software  licenses  you 
have,”  IDC’s  Burden  notes. 


DO’S  AND  DON’TS  OF  ASSET 
MANAGEMENT 


Start  Slowly 

Once  a  company  chooses  an  asset  management  strategy  and 
package,  the  temptation  is  to  install  everything  as  quickly  as  pos¬ 
sible.  That  can  be  a  big  mistake.  “If  you  try  to  do  it  all  at  once, 
you  are  going  to  run  into  a  lot  of  organizational  boundaries. 
Start  in  one  area,  like  help  desk,  where  you  only  have  to  deal 
with  gathering  inventory  data  so  that  you  can  distribute  soft¬ 
ware  more  rapidly  or  provide  technical  support  resources  more 
readily,”  advises  Christopher  Germann,  MainControl’s  vice 
president  of  corporate  strategy.  “Or  you  could  start  on  the 
finance  side,  focusing  on  keeping  track  of  all  of  the  different 
machines  under  lease.” 

Burden  agrees.  “To  show  success,  start  by  attacking  a  prob¬ 
lem  you  know  you  can  solve,”  he  says.  “Turning  on  all  the 
modules  at  once  is  overwhelming,  and  you  are  dooming  your¬ 
self  to  failure.” 

That  incremental  approach  is  the  one  American  Home 
Products  took.  The  company  began  by  implementing  its  asset 
management  system  only  in  the  pharmaceutical  division’s  20 
U.S.  sites  but  plans  to  extend  it  worldwide  within  the  next 
year  or  so.  Bluestone  believes  the  project  would  have  failed 
otherwise.  “You  are  inviting  yourself  into  each  functional 
group’s  work  stream,  and  each  one  entails  a  completely  differ¬ 
ent  process.  You  have  to  understand  how  people  use  their  assets 
and  leverage  the  resources  within  those  groups  to  get  the  data  in 
the  form  you  need  it.  That  takes  time.  The 
only  way  to  do  it  is  by  implementing  a 
phased  approach,”  he  says. 

Payback 

Implementing  an  asset  management  system 
is  far  from  cheap,  but  experts  and  users 
alike  believe  the  rewards  can  be  enormous. 
For  example,  Peregrine  Systems’  asset  man¬ 
agement  applications  cost  anywhere  from 
$80,000  to  $150,000  for  the  software 
alone,  and  another  $90,000  to  $180,000 
for  training,  installation  and  customization. 
Both  Marriott’s  Wilson  and  Williams’ 
Tucker  say  those  prices  are  typical  but 
stress  that  the  costs  are  small  when  com¬ 
pared  with  the  savings  these  kind  of  sys¬ 
tems  can  generate. 

For  example,  on  the  hardware  side,  it 
can  cost  anywhere  from  $300  to  $1,800 
per  machine  to  have  a  computer  moved  or 
reconfigured.  Sometimes  it’s  actually 
cheaper  to  dispose  of  that  piece  of  equip¬ 
ment  and  bring  in  a  new  one,  and  asset 
management  systems  can  help  determine 


SI 


o’s 


Do  focus  on  soft  cost  savings. 

Do  get  buy-in  from  upper 
management. 

Do  determine  your  “pain  points”- 
the  areas  that  would  benefit  the 
most  from  asset  management- 
before  you  begin. 

Do  go  for  the  biggest  return  on 
investment  first;  that  way,  you 
reward  your  executive  sponsors. 


mm 


Don’t  neglect  the  hard  work  of  setting 
practices  and  policies  within  your 
company  to  make  the  system  truly 
effective. 

Don’t  think  of  asset  management  as 
an  accounting  system;  it  is  a  way  to 
manage  the  accounting  of  an  asset. 

Don’t  try  to  do  everything  at  once;  start 
slowly  and  expand  as  it  makes  sense. 

Don’t  expect  results  overnight;  asset 
management  is  a  long-term  process. 

-K.  Schwartz 


148  CIO  JUNE  1,  2000  •  www.cio.com 


Immediate  access  to  relevant  data  is  vital  to  your  success.  Availability 
of  up-to-date  information  becomes  the  crucial  factor  to  beat  the 
competition  in  this  challenging  new  economy.  delivers 

best-in-class  Web-solutions  for  leveraging  the  information  stored  in 
your  systems  and  offers  a  powerful  way  of  creating  intuitive  and 
seamless  OLAP  applications  integrated  with  your  IT  infrastructure. 
Maximize  the  return  on  your  technology  investment  with  the  leading 
solution  for  enterprise  information  systems. 


a  isi  d 


arcplan 

Information  Systems 


www.arcplan.com 


The  vision  to  see  beyond  with  interfaces  to  SAP™  R/3  SAP™  BW\  Hyperion  Essbase™,  Hyperion  Enterprise™,  Applix  TM1™, 
MS  OLAP  Services™,  MIS  ALEA™,  Informix  MetaCube™,  Oracle  Express™,  ODBC  and  OLE  DB,  XML. 


Asset  Management 


that.  Bluestone  estimates  that  his  company  can  conservatively 
save  about  $1  million  over  a  three-year  period — and  those 
are  just  the  hard  costs.  Reducing  soft  costs  like  managing  IT 
leasing  transactions,  invoice  reconciliation  and  time  spent 
gathering  ad  hoc  asset  inventories,  which  are  hard  to  mea¬ 
sure  but  add  up  quickly,  will  yield  considerable  additional  sav¬ 
ings,  he  says.  Sears’  Ben  says  her  company  estimates  a  six- 
month  payback  through  better  management  of  leases,  tech¬ 
nology  redeployment  and  reuse,  and  lower  TCO  for 
workstations.  “Our  goals  are  to  reduce  TCO  on  an  ongoing 


provider  (ASP)  model.  It  may  be  a  confusing  time  for  companies 
as  they  try  to  manage  software  bought  under  old-style  agree¬ 
ments  along  with  software  rented  through  an  ASP.  Even  so, 
asset  management  will  probably  shift  away  from  being  a 
“power  user”  application  to  a  self-service  application. 

The  ASP  model  will  undoubtedly  affect  the  way  American 
Home  Products  licenses  software,  pays  maintenance  fees  and 
deploys  technology  capabilities,  Bluestone  says.  “From  an  over¬ 
all  process  perspective,  asset  management  will  become  even 
more  critical  for  enterprises  considering  ASP  hosting,”  he  says. 


Until  companies  get  a  thorough  understanding  of  their  IT  assets, 
if  s  impossible  for  them  to  effectively  control  their  costs.’ 

-Kevin  Burden,  senior  analyst,  DDC 


basis  of  3  percent  to  5  percent  per  year  with  significant  one¬ 
time  reductions  as  each  asset  is  brought  under  better  con¬ 
trol,”  she  adds. 

Many  companies’  chief  concern  is  decreasing  TCO  and 
increasing  return  on  investment,  and  soft  cost  savings  are  vital 
to  accomplishing  those  goals.  It’s  common  for  some  CIOs  to 
overlook  the  power  of  reducing  soft  costs — something  a  for¬ 
mal  asset  management  strategy  can  help  correct.  “CIOs  know 
these  soft  costs  exist,  but  they  don’t  know  how  to  measure  them 
or  control  them.  Indirect  costs  often  don’t  get  written  into  the 
balance  sheet,  so  they  are  often  overlooked,”  Burden  says. 

Another  soft  cost  savings  strategy  involves  help  desk  support. 
By  having  information  on  all  the  company’s  computers  on  one 
system,  a  help  desk  employee  can  see  a  profile  of  all  equipment 
and  training  an  employee  has  within  a  few  seconds  of  typing 
in  that  employee’s  name  and  ID.  That  reduces  call  time  because 
help  desk  staffers  don’t  have  to  ask  as  many  questions. 

The  Future  of  Asset  Management 

Many  organizations  still  manage  their  assets  in  a  haphazard 
way,  but  because  of  the  proliferation  of  PCs  in  the  business  envi¬ 
ronment,  the  pressures  of  internet  time  and  the  structure 
imposed  by  Y2K  remediation,  that  is  changing.  Two  or  three 
years  ago,  you’d  have  been  hard-pressed  to  find  an  asset  man¬ 
agement  department  or  even  an  employee  with  the  title  of  Asset 
Manager,  but  it  is  no  longer  such  a  rarity. 

Asset  management  practices  are  no  more  static  than  a  com¬ 
pany’s  technology  infrastructure.  The  popularity  of  the  inter¬ 
net  for  delivering  software  and  licensing  models  means  new 
delivery  mechanisms  and  contracts.  Asset  management  sys¬ 
tems  will  change  to  support  trends  toward  outsourcing  software 
applications  and  management  through  the  application  service 


American  Home  Products  has  come  a  long  way  since  it 
began  implementing  asset  management  in  1998.  As  of  this 
spring,  the  pharmaceutical  division  has  accomplished  its  enter¬ 
prise  asset  management  objectives  from  an  architectural,  pro¬ 
gram  and  process  management  perspective.  The  division  has  a 
single  corporate  system  for  recording  IT  assets  and  contracts 
and  consistent  asset  management  processes  across  the  board. 
Still,  Bluestone  and  his  team  continue  to  push  the  envelope 
with  a  carefully  planned,  phased  approach  that  includes  making 
enhancements  both  to  Argis  and  NetCensus.  Currently, 
Bluestone ’s  team  is  working  on  an  initiative  to  provide  “dash¬ 
board”  enterprise  asset  management  information  and  online 
reporting  tailored  to  senior  IT  management  and  IT  clients  via  its 
Global  IT  Sourcing  intranet  site,  and  it  is  also  planning  links 
to  the  company’s  problem  management  system  from  Santa 
Clara,  Calif.-based  Vantive  Corp.  (now  part  of  PeopleSoft)  and 
to  its  SAP  Fixed  Assets  implementation. 

Choosing  the  right  asset  management  system  is  complex,  and 
managing  the  system  is  an  ongoing  effort,  but  taking  the  plunge 
is  well  worth  it,  Burden  says.  “Many  companies  look  at  the 
whole  thing  as  a  huge  expense.  But  chances  are,  most  large 
companies  have  more  IT  equipment  than  their  managers  think 
they  do.  They  think  everything  is  fine,  but  they  have  more  PCs 
than  they  have  employees,  duplicate  software  licenses  and 
shelves  full  of  old,  decommissioned  systems,”  he  says.  “And 
until  companies  operating  like  that  get  a  thorough  understand¬ 
ing  of  their  IT  assets,  it’s  impossible  for  them  to  effectively  con¬ 
trol  their  costs,  efficiently  install  new  technologies  or  even  max¬ 
imize  the  use  of  the  technologies  already  in  place.”  BE] 


Karen  D.  Schwartz  is  a  freelance  writer  specializing  in  business  and 
technology.  She  can  be  reached  at  karen.schwartz@bigfoot.com. 


150  CIO  JUNE  1,  2000  •  www.cio.com 


. 


-•■  ■'jMtijajggm 

iimmms 


COMDISCO 


The  issue  is  availability:  Your  web  site’s  acting  up,  your  customers  want  access  to  your  business,  and  all  you  want  is  sleep.  You  need  an 


availability  partner  you  can  trust.  A  partner  with  20  years  of  technology  services  experience  and  50  worldwide  technology  centers.  Not  to 


mention  a  perfect  track  record  in  providing  availability.  We’re  at  1-800-272-9792.  www.comdisco.com.  Delivering  the  promise  of  technology 


Case  Files 


Knowledge  Management 


How  the  Tennessee  Valley  Authority’s 
nuclear  division  saved  time  and  money 
by  integrating  machine-maintenance 
knowledge  and  workflow  processes 

BY  CAROL  HILDEBRAND 


FOR  MOST  COMPANIES,  improper  machine  maintenance  is 
probably  a  matter  of  lost  profits:  A  little  downtime,  a  screwed-up 
order,  an  unhappy  customer.  The  Tennessee  Valley  Authority’s  nuclear 
division  must  play  for  higher  stakes,  however.  For  them,  mainte¬ 
nance  could  be  a  matter  of  life  and  death. 

That’s  why  the  TVA,  the  nation’s  largest  public  power  supplier, 
overhauled  its  nuclear  division’s  maintenance  management  system, 
creating  a  centralized  knowledge  management  system  that  cuts  time 
and  errors  out  of  the  cycle. 

Serving  nearly  8  million  customers,  TVA  uses  a  mixture  of  fossil, 
hydroelectric  and  nuclear  energy.  TVA  Nuclear’s  three  facilities  represent  about  20  percent 
of  TVA’s  generating  capacity.  After  analyzing  TVA’s  major  business  processes,  a  group  of 
TVAN  senior  executives  targeted  the  maintenance  management  process  at  TVAN  as  a  prime 
candidate  for  improvement.  For  one  thing,  the  tools  currently  used  were  not  Y2K  compli¬ 
ant;  for  another,  maintenance  work  relies  heavily  on  documents  such  as  vendor  manuals, 
drawings  and  formally  regulated  work  instructions. 

“It’s  document  management,  which  requires  so  much  paper,  that  it’s  always  a  target,” 
says  Karl  Singer,  senior  vice  president  of  nuclear  operations  at  TVA.  TVAN  estimates  that 
nearly  $48.7  million  was  spent  annually  generating,  planning  and  performing  maintenance 
work  orders  in  this  heavily  regulated  and  safety  conscious  industry.  The  executives  tapped 
individuals  from  various  groups  at  the  Browns  Ferry  Nuclear  Plant  to  develop  and  pilot  the 
program,  with  input  from  the  folks  at  the  two  other  nuclear  plants  in  the  TVA  network. 


The  Company:  The 
Tennessee  Valley  Authority 

Founded  1933  Location  The  seven-state  Tennessee 
Valley  region  Revenues  $6.6  billion  Employees  13,322 
KM  Problem  Providing  TVA’s  nuclear  division  with  access 
to  information  about  plant  equipment  (maintenance  and 
operating  protocols,  vendor  information,  drawings) 

URL  www.tva.gov 


1  5  2 


CIO 


JUNE  1 


2000 


www.cio.com 


PHOTO  BY  MATTHEW  BARNES 


They  needed  to  couch  the  new 
system  in  terms  of  the  overall 
versus  the  individual  benefits. 


TVA  Nuclear’s  project  team  (from  left):  Karl  Singer,  Donnie  Martin.  Sonja  Bridges, 
Dale  Johnson,  Robert  Rupe 


The  group  started  by  analyzing  the  current 
state  of  affairs,  looking  for  places  to  consol¬ 
idate  work  and  deciding  what  performance 
metrics  they  most  wanted  to  improve,  says 
Robert  Rupe,  the  process  improvement 
manager  at  TVAN  and  the  person  responsi¬ 
ble  for  coordinating  TVAN’s  various  process 
improvement  efforts.  Since  more  than 
14,000  work  orders  are  written  annually  at 
Browns  Ferry  alone,  there  was  room  for  sig¬ 
nificant  savings  through  productivity 
improvements.  They  then  charted  the  exist¬ 
ing  work-order  and  procedures-management 
processes,  conducting  more  than  350  hours 
of  interviews  with  plant  employees  and  also 
benchmarking  the  maintenance  processes  of 
15  utilities  and  six  other  companies. 

One  of  the  big  “ahal’s”  says  Rupe,  was 
just  how  closely  the  planning  and  execution 
of  maintenance  work  orders  was  linked  to 
procedures  management  and  document 
workflow.  For  example,  a  typical  handwrit¬ 
ten  work  order  came  attached  to  various 
paper  copies  of  machine  diagrams,  docu¬ 


mentation  and  procedural  instructions.  But 
the  work  orders  lagged  behind  document 
and  procedural  revisions.  “Most  of  our 
work  is  planned  two  months  ahead  of  time,” 
says  Rupe,  and  some  orders  are  planned  six 
months  to  a  year  in  advance.  Meanwhile, 
“We’re  constantly  getting  new  procedural 
updates  from  the  outside,  so  stuff  gets  revised 
fairly  frequently,”  he  says. 

After  six  months  of  full-time  work  by 
seven  people,  the  group  produced  a  work 
process  that  combined  maintenance  order 
workflow  with  procedural  document  man¬ 
agement.  They  built  two  integrated  systems 
that  would  support  the  new  processes  by 
linking  procedural  documents  electronically 
to  the  work  management  system.  That 
process  would  eliminate  five  or  six  separate 
software  packages  that  did  not  speak  to  each 
other  or  share  a  common  interface. 


There  was  no  off-the-shelf  software  avail¬ 
able,  so  the  team  partnered  with  a  vendor 
(The  System  Works,  since  purchased  by  Indus 
Corp.)  in  an  arrangement  that  gave  process 
requirements  to  the  vendor,  who,  in  turn, 
built  a  commercial  product  around  those 
specifications.  In  essence,  says  Rupe,  “We 
helped  define  a  new  off-the-shelf  product.” 

The  resultant  new  system  took  28  months 
from  first  brainstorm  to  rollout,  says  Rupe. 
It  gives  workers  desktop  access  to  docu¬ 
mentation  on  assets,  records,  equipment 
and  parts  information,  and  work  instruc¬ 
tions  for  all  three  sites.  Now,  a  work  order 
is  generated  electronically,  routed  for 
approval  and  attached,  also  electronically, 
to  the  most  recent  batch  of  pertinent  draw¬ 
ings  and  documentation. 

Moreover,  the  electronic  documents  are 
indexed  down  to  each  piece  of  equipment 


www.cio.com 


JUNE  1,  2000  CIO  15  3 


Case  Files  Knowledge  Management 

in  the  plant.  All  three  nuclear  plants  are  now 
standardized  on  the  systems,  and  the  main¬ 
tenance  groups  can  draw  on  the  repository 
of  previously  completed  work  orders  to  ana¬ 
lyze  and  manage  future  activity  more 
effectively. 

Lessons  Learned 

After  spending  so  much  time  on  the  analytical 
and  design  side,  Rupe  says,  “We  butchered 
change  management.”  The  worst  mistake 
was  grossly  underestimating  the  computer  lit¬ 
eracy  of  the  workforce,  he  says.  There  were 
people  who’d  never  used  a  keyboard,  and 
people  who  thought  the  CD-ROM  drive  was 
a  coffee  cup  holder.  The  lesson  that  TVAN 
took  away,  says  Rupe,  was  twofold. 

First,  the  rollout  team  needed  to  get  basic 
computer  skills  up  to  a  standard  level.  But 
more  important,  the  group  needed  to  couch 
the  new  system  in  terms  of  how  it  improved 
the  overall  process  rather  than  what  each 
individual  would  see.  “Because  we  went  to 
distributed  computers,  some  of  the  response 
times  were  actually  slower,  and  people  saw 
that.  But  we  didn’t  explain  that  the  overall 
process  would  result  in  huge  time  savings.  We 
needed  to  manage  expectations  better.” 

The  system  wasn’t  cheap:  It  cost  about 
$5.1  million  initially,  and  more  upgrades  are 
planned.  But  the  savings  are  equally  impres¬ 
sive:  The  time  it  took  to  process  a  work 
order  dropped  from  39.8  to  23.3  person- 
hours  per  order,  and  TVAN  saved  an  esti¬ 
mated  $8.4  million  annually  in  labor  costs. 
And,  Rupe  says,  in  an  industry  driven  by  cost 
savings,  that’s  a  big  payback. 

More  important,  however,  the  system 
helps  maintenance  workers  learn  from  cap¬ 
tured  data.  It  might  be  something  as  mun¬ 
dane  as  noticing  that  the  label  on  a  valve 
doesn’t  match  the  label  on  a  drawing;  but 
in  the  end,  such  a  mundane  thing  can  add 
up  to  safety  for  millions.  As  Rupe  says,  “This 
is  a  business  that  requires  precision.”  0EJ 


Have  you  had  success  with  a  knowledge  manage¬ 
ment  project?  Senior  Editor  Carol  Hildebrand  wants 
to  know.  E-mail  her  at  cjh@cio.com. 

154  CIO  JUNE  1,  2000  •  www.cio.com 


EXPERT  ANALYSIS  BY  THOMAS  H.  DAVENPORT 

Power  to  the  People 

TVA's  is  a  fine  example  of  information  systems  practice,  replete  with  the  typical 
change-management  problems  and  a  pretty  decent  financial  payoff.  My  question, 
however,  is  whether  it  is  really  knowledge  management.  A  few  years  back,  it  would 
clearly  have  been  called  a  document  management  and  workflow  system.  Why 
adopt  the  newfangled  terminology?  Maintenance  documents  such  as  those  cap¬ 
tured  and  managed  by  the  TVA  system  can  obviously  con¬ 
tain  knowledge.  But  accessing  and  distributing  documents 
electronically  was  possible  long  before  knowledge  manage¬ 
ment  and  can  be  accomplished  through  a  variety  of  means— 
not  only  workflow,  but  intranets,  e-mail,  electronic  publish¬ 
ing  and  so  on.  Are  all  of  these  knowledge  management 
applications? 

To  my  conservative  mind,  whether  this  is  a  knowledge 
management  application  rises  and  falls  on  one  factor:  that 
is  whether  the  knowledge  flows  to  and  from  the  mainte¬ 
nance  workers.  A  system  that  distributes  documents  along 
the  maintenance  process  is  a  document  management  sys¬ 
tem.  A  system  that  allows  maintenance  workers  to  record 
their  own  observations  about  the  documents,  the  process 
and  their  day-to-day  use  on  the  job  is  a  knowledge  man¬ 
agement  system. 

When  I  talked  to  Robert  Rupe  at  TVA,  he  said  that  main¬ 
tenance  workers  have  some  ability  to  modify  the  system’s 
knowledge.  They  can  note  that  the  work  plan  is  inaccu¬ 
rate— for  example,  they  can  see  that  the  plan  didn’t  say  if 
insulation  had  to  be  taken  off  before  changing  a  valve.  Or  they  can  determine  if 
scaffolding  is  necessary  to  do  the  job  safely.  These  workers  note  such  issues  on 
paper,  which  later  gets  scanned  into  the  system  for  planners  to  notice  and  use. 
What’s  particularly  reassuring  is  that,  while  Rupe  says  they  didn’t  call  it  knowledge 
management  when  they  built  the  system,  sharing  knowledge  within  nuclear  plants 
and  across  the  industry  is  an  extremely  important  goal  in  the  post-Three  Mile 
Island  world.  When  we’re  talking  about  nuclear  power,  I  personally  would  like  to 
see  everyone  using  their  brains  and  sharing  knowledge  to  the  maximum  degree 
possible. 

So  let’s  say  that  the  TVA  maintenance  application  is  at  least  a  knowledge- 
oriented  system.  Although  it’s  not  the  sexiest  application  around,  its  existence  is 
good  news  for  knowledge  management.  It  suggests  that  knowledge  management  is 
making  its  way  into  the  down-and-dirty  parts  of  organizations.  It  points  out  that 
knowledge  is  an  important  resource  not  just  for  white-collar  knowledge  workers 
but  for  people  who  use  wrenches  and  valves  and  flanges  as  well.  The  system  also 
indicates  that  we  are  finally  starting  to  embed  knowledge  into  jobs  rather  than 
adding  it  on  top  of  them. 

The  TVA  analysts  were  diligent  about  ensuring  that  the  flow  of  knowledge  was 
integrated  with  the  flow  of  the  maintenance  process.  I  hope  that  we’ll  see  more 
hybrids  of  process  redesign  and  knowledge  management  in  the  future. 


Tom  Davenport  is  a 
professor  of  manage¬ 
ment  information 


systems  at  Boston 
University  School  of 
Management  and 
director  of  the 
Andersen  Consulting 
Institute  for  Strategic 
Change.  He  welcomes 
reader  comments  at 
davenport@cio.com. 


PHOTO  BY  FURNALD/GRAY 


Qwest  Q  Port."  No  limit  networking.  Can  you  imagine 
a  network  that  delivers  the  bandwidth  you  need  without 
it  costing  you  a  fortune.  Qwest  Q  Port  can  make  it  happen. 
Because  only  QPort  gives  you  Frame  Relay  and  a 
simple  migration  path  to  IP  for  one  flat  monthly  fee. 
Which  means  you  can  bank  on  bandwidth  without 
blowing  your  budget. 

To  find  out  more  about  QPort,  visit  www.qwest.com  or 
call  1  800  RIDE  QWEST  (1-800-743-3793).  Because 
from  today,  there  will  be  no  limits. 


ride  the  light 


Qwest 


Book  Excerpt 


Harnessing  Complexity 


As  Linux  demonstrates, 

one  way  to  ensure  coherence 
in  a  complex  world 

is  to  encourage  variety 


15  6  CIO  JUNE  1,  2000 


www.cio.com 


BY  ROBERT  AXELROD  AND  MICHAEL  D.  COHEN 


henever  we  forge  new  strategies,  devise  new  policies  or  cre¬ 
ate  new  services,  we  are  dabbling  in  the  world  of  complex 
adaptive  systems.  Authors  Robert  Axelrod  and  Michael  C. 
Cohen  define  a  complex  adaptive  system  as  one  in  which 
a  single  action— such  as  putting  up  a  website— can  lead  to  unforeseen,  even  un¬ 
predictable  consequences.  Their  new  book,  Harnessing  Complexity:  Organizational 
Implications  of  a  Scientific  Frontier  (The  Free  Press,  1999),  aims  to  help  read- 


From  Harnessing 
Complexity:  Organizational 
Implications  of  a  Scientific 
Frontier  by  Robert  Axelrod 
and  Michael  D.  Cohen. 
Copyright  1999  by  Robert 
Axelrod  and  Michael  D. 
Cohen.  Reprinted  by 
permission  of  Free  Press/ 
Simon  &  Schuster. 


www.cio.com  •  JUNE  1,  2000  CIO  157 


ILLUSTRATIONS  BY  MATTHEW  TRUEMAN;  PHOTO  BY  VITO  ALUIA 


Book  Excerpt 


Harnessing  Complexity 


ers  understand  how  to  design  organizations 
and  strategies  in  a  complex  environment. 
Borrowing  ideas  from  scientific  and  biologi¬ 
cal  research  in  which  three  factors — varia¬ 
tion,  interaction  and  selection — shape  com¬ 
plex  environments,  the  authors  have  devised 
a  framework  as  a  way  of  guiding  readers  to 
pose  new  questions  and  ponder  new  possi¬ 
bilities  when  confronted  with  complexity. 

Why  do  the  authors  feel  now  is  a  particu¬ 
larly  appropriate  time  to  apply  complexity 
theory  to  business?  It  all  has  to  do  with  the 
information  revolution.  Given  the  number  of 
people  and  organizations  that  interact  in  a  net¬ 
worked  economy,  the  unpredictable  nature 
of  business — and  indeed  of  daily  life — is  accel¬ 
erating.  The  pace  and  scope  of  adaptation 
is  faster,  resulting  in  social  and  organiza¬ 
tional  upheaval.  In  the  following  excerpt,  the 
authors  use  the  development  of  Linux  as  an 
example  of  variation.  The  question  they  pon¬ 
der:  When  can  an  organization  or  population 
do  better  with  more  variety  as  opposed  to  uni¬ 
formity?  The  answer  revolves  around  the 
principle  of  exploration  versus  exploitation, 
a  trade-off  situation  between  creating  strate¬ 
gies  that  are  untested  but  may  be  superior  to 
what  exists  versus  copying  proven  strategies. 


E  CAN  ILLUSTRATE 
the  conditions  that 
favor  encouraging 
variety  by  consider¬ 
ing  the  striking  case 
of  the  Linux  com¬ 
puter  operating  sys¬ 
tem  and  the  method  used  to  organize  the 
work  of  its  developers.  The  method  is  known 
as  open  source  software  development.  This 
form  of  software  development  has  been 
thrown  into  the  limelight  by  the  spectacu¬ 
lar  growth  of  Linux,  which  has  become,  in 
certain  key  areas  of  application,  a  serious 
competitor  to  operating  systems  developed 
and  sold  by  major  corporations  such  as 
Microsoft,  Sun  and  IBM. 

This  is  a  very  surprising  turn  of  events 
since  Linux  is  given  away  free  by  its  devel¬ 
opers.  There  is  a  natural  presumption  that 


free  software  cannot  be  as  reliable  as  for- 
profit  software.  Yet  it  is  precisely  for  situa¬ 
tions  demanding  high  reliability  that  Linux 
has  found  its  strongest  support. 

The  surprise  deepens  with  the  observa¬ 
tion  that  Linux  is  not  only  free  but  also 
the  handiwork  of  an  enormous,  worldwide 


sufficient  motivation  can  craft  changes  to 
the  code,  creating  a  new  version  of  the  pro¬ 
gram.  This  is  not  possible  in  traditional  de¬ 
velopment  with  proprietary  code.  From  a 
Complex  Adaptive  Systems  point  of  view, 
the  possibility  for  volunteers  to  create 
working  variants  increases  massively  the 


^  ariety  is  the  engine  of  rapid  quality 
improvement  in  an  open  source  initiative. 


cadre  of  unpaid  volunteers.  By  some  esti¬ 
mates,  Linux  is  the  result  of  contributions 
from  many  thousands  of  programmers.  A 
computer  operating  system  is  one  of  the 
most  intricate  of  human  creations.  This 
number  of  cooks  would  seem  more  than 
sufficient  to  spoil  the  soup.  How  could 
thousands  of  scattered  volunteers  make  an 
operating  system  that  is  more  reliable  (and 
faster  running)  than  those  created  by 
dozens,  or  hundreds,  of  highly  talented 
programmers  working  full  time  for  re¬ 
nowned  corporations? 

Considering  the  development  of  Linux 
as  a  Complex  Adaptive  System  casts  light  on 
some  important  components  of  the  expla¬ 
nation.  We  can  begin  by  pointing  out  that 
Linux  is  not  the  only  example  of  the  open 
source  approach  to  software  development. 
There  are  many  earlier  examples,  such  as 
the  scripting  language  Perl  and  the  e-mail 
server  Sendmail.  The  most  widely  deployed 
software  for  serving  up  requested  World 
Wide  Web  pages,  a  system  known  as  Ap¬ 
ache,  is  also  the  product  of  volunteers  work¬ 
ing  together  in  an  open  source  framework. 
What  all  the  examples  have  in  common  is 
the  free  availability  of  the  source  code,  the 
human  readable  computer  instructions  that 
specify  the  program.  That  arrangement  pro¬ 
vides  the  generic  label  for  this  approach  to 
team  software  creation:  open  source  soft¬ 
ware  development. 

The  free  access  to  the  source  code  of 
Linux  means  that  any  programmer  with 


variety  of  the  population  of  operating  sys¬ 
tems.  In  successful  open  source  cases  such 
as  Linux,  that  variety  has  been  harnessed 
to  yield  a  very  effective  result,  although 
many  observers  expected  chaos  to  result 
from  the  rapid  injection  of  many  potentially 
incompatible  variants. 

Our  framework  points  to  several  struc¬ 
tural  arrangements  that  work  to  make  the 
added  exploration  beneficial,  averting  the 
prospect  of  death  by  eternal  boiling.  [Eternal 
boiling  occurs  when  the  level  of  mutation  is 
so  high  that  a  system  remains  in  a  permanent 
state  of  disorder.]  In  our  terms,  when  a  pro¬ 
grammer  modifies  the  source  code  of  Linux, 
this  activity  is  an  endogenously  triggered 
recombination.  The  trigger  is  usually  an  ob¬ 
servation  of  some  particular  kind  of  poor 
performance  by  the  existing  standard  version 
of  the  operating  system.  The  affected  user 
may  make  an  electronic  request  for  help 
from  the  large  Linux  community.  Interested 
individuals  respond  by  suggesting  fixes. 
These  small  pieces  of  new  code  are  recom¬ 
bined  with  the  rest  of  the  standard  version 
to  produce  new  variant  versions.  A  period 
of  testing  and  discussion  of  the  performance 
of  the  variants  follows.  Eventually  the  best¬ 
performing  variant  is  accepted  by  the  small 
team  of  key  Linux  developers,  who  incor¬ 
porate  the  new  code  into  a  subsequent  stan¬ 
dard  version  of  Linux. 

When  open  source  development  pros¬ 
pers,  a  central  reason  seems  to  be  that,  as 
Eric  S.  Raymond  says,  “given  enough  eye- 


* 


According  to  Internet  experts, 

the  Internet  will  introduce  new  ways 

for  Internet  experts  to  talk  about  the  Internet. 


www.iplanet.com 


r 

L 


i  Planet 

e-commerce  solutions 


Book  Excerpt 


Harnessing  Complexity 


balls,  all  bugs  are  shallow.”  For  Linux,  there 
are  certainly  enough  volunteers.  Equally  im¬ 
portant,  the  communication  among  volun¬ 
teers  about  triggering  problems  and  pro¬ 
posed  alternatives  is  precise  enough  that 
multiple  plausible  variants  are  routinely  gen¬ 
erated  as  possible  solutions  to  most  prob¬ 
lems  that  bother  users.  In  addition,  testing  of 
alternatives  is  reliable  enough  that  the  code 
that  wins  out  is  generally  very  good  code, 
with  unwanted  side  effects  being  rare.  Thus 
the  variety  made  possible  by  the  free  avail- 


,r\n  improvement 
to  an  operating 
system  is  likely  to 
bear  fruit  over  a 
very  long  period. 


ability  is  marshaled  to  produce  a  rapid  rate 
of  improvement  in  overall  quality7.  By  inquir¬ 
ing  a  bit  further  into  how7  this  is  accom¬ 
plished,  w7e  can  uncover  some  clues  about 
when  an  open  source  approach  is  likely  to 
w7ork  w7ell — and  when  it  is  not. 

A  crucial  fact  is  that  there  are  two  types 
of  Linux  versions:  standard  and  variant. 
The  few  central  managers  of  the  Linux 
community,  led  by  the  originator  of  the 
operating  system,  Linus  Torvalds,  retain 
the  right  to  label  versions  of  the  system  as 
official  releases.  Each  new7  official  release 
creates  another  “standard  Linux,”  and 
millions  of  digitally  perfect  copies  are 
made  of  it. 

This  control  over  the  definition  of  the 
next  generation  of  the  operating  system  is 
strikingly  analogous  to  a  biological  mech¬ 
anism  seen  in  the  emergence  of  multicellu¬ 
lar  organisms:  sequestration  of  the  germ 


activity  to  a  few  specialized  cells,  w7hile  the 
vast  majority7  of  cells  in  the  organism  no 
longer  participate  in  creating  the  next  gen¬ 
eration.  In  both  cases,  limiting  “reproduc¬ 
tion”  to  a  tiny  fraction  of  all  the  agents 
reduces  the  chaotic  inconsistency  that  would 
follow7  if  all  variants  had  equal  opportu¬ 
nity7  to  shape  the  future. 

In  the  Linux  case,  the  centralized  con¬ 
trol  of  changes  in  the  standard  code  makes 
higher  levels  of  variety  in  the  proposed 
changes  sustainable,  so  that  the  “law  of  suf¬ 
ficient  eyeballs”  can  come  advantageously 
into  play.  In  the  biological  case,  the  restric¬ 
tion  functions  to  alter  the  evolutionary 
“incentives”  of  cells  making  up  the  organ¬ 
ism.  Over  succeeding  generations  their  strate¬ 
gies  w7ill  be  far  more  likely  to  be  those  that 
let  them  prosper  as  a  “team”  rather  than 
those  that  benefit  individual  cells  at  the 
expense  of  the  others.  Analogous  incentives 
are  created  for  the  programmers  in  the 
Linux  case. 

Numerous  experiments  are  being  under¬ 
taken  in  an  effort  to  imitate  the  striking  suc¬ 
cess  that  the  open  source  approach  achieved 
in  the  Linux  case.  As  usual,  w7e  do  not  claim 
to  be  able  to  predict  the  success  and  failure  of 
particular  efforts.  But  Complex  Adaptive 
Systems  principles  do  suggest  a  number  of 
key  questions  to  ask  w7hen  contemplating  an 
open  source  software  project.  As  w7e  have 
seen,  variety  is  the  engine  of  rapid  quality 
improvement  in  an  open  source  initiative. 

We  can  see  that  Linux  has  at  least  three, 
and  perhaps  all  four,  of  the  conditions  favor¬ 
ing  exploration. 

1  Problems  that  are  long-term  or  wide¬ 
spread.  In  contrast  to  computer  hard¬ 
ware  and  applications  programs  (such 
as  wreb  browsers),  operating  systems  are 
among  the  longest  living  elements  of  the 
computational  world.  Unix — of  which  Li¬ 
nux  is  a  free  version — dates  back  to  1969. 
It  runs  on  mainframe  and  minicomputer 
architectures  that  long  predate  the  micro¬ 
computers  that  now7  cover  the  earth.  Thus, 
an  improvement  to  an  operating  system  is 


likely  to  bear  fruit  over  a  very  long  period 
(as  time  is  measured  in  the  strange  universe 
of  computing,  with  its  Moore’s  Law  of 
doubled  computer  power  every  18 
months).  Another  example  of  open  source 
development,  the  Apache  web  server,  also 
seems  to  occupy  a  functional  niche  where 
improvements  can  be  expected  to  have 
long  service.  In  addition,  the  gains  from 
any  improvement  in  a  standard  version  of 
an  operating  system  can  benefit  thousands 
or  even  millions  of  users,  providing  wide¬ 
spread  benefits. 


2  Problems  that  provide  fast,  reliable 
feedback.  Linux  exhibits  this  charac¬ 
teristic  as  well.  In  its  typical  role  in 
server  environments,  its  features  are  exer¬ 
cised  at  very  high  rates,  and  defects  become 
evident  quickly.  Moreover,  open  source  dis¬ 
tribution  means  that  every  contributor  of  a 
proposed  variant  can  make  a  completely 
functional  new  version  that  can  be  tested 
locally.  This  further  increases  the  rate  of  feed¬ 
back.  And  finally,  the  quality  of  proposed 
variants  can  be  assessed  with  relatively  high 
reliability.  Speed  of  operation  and  resistance 
to  crashes  are  highly  valued  criteria  across 
the  entire  community  of  Linux  developers. 
Disagreements  do  occur  over  how  these 
should  be  measured,  and  other  criteria  are 
also  important.  But  when  compared  with 
other  software  areas,  such  as  user  interface 
design,  the  appropriate  performance  met¬ 
rics  are  relatively  clear. 


3  Problems  with  low  risk  of  catastro¬ 
phe  from  exploration.  Various  parts 
of  a  software  system  have  high  levels 
of  interdependence.  When  there  is  a  pre¬ 
mium  on  speed,  as  there  is  for  many  oper¬ 
ating  systems,  there  is  a  strong  temptation 
to  increase  even  further  the  interdependen¬ 
cies  among  modules.  This  can  create  a  sub¬ 
stantial  risk  of  catastrophe.  But  Unix,  from 
w7hich  Linux  derives,  has  long  been  a  par¬ 
tial  exception  to  this  tendency.  In  the  Unix- 


Linux  culture  there  is  a  well-developed  phil- 


KICKING 


What  are  you  waiting  for?  Get  our  new,  scalable,  high-performance  server 
appliances  that  are  only  1U  high,  built  with  lights-out  remote  management 
and  pre-configured  so  you  can  just  plug  them  in  and  go.  Because  the  Internets 
a  kick  or  be  kicked  world  and,  frankly,  which  would  you  prefer?  877-865-1161 


networkengmes 


www.networkengines.com 


©2000  Network  Engines 


arn 

IT  Leadership 
from  the 


Best 


in  the 


Business! 


COMPVTERWORLD 

1AA 


PREMIER 


IT  LEADERS 

CONFERENCE 


June  19-21, 2000 
Marriott  Desert  Springs 
Resort  &  Spa 
Palm  Desert,  CA 


At  Computerworld’s  Premier 
100  IT  Leaders  Conference, 
June  19-21, 2000  at  the 
Marriott  Desert  Springs  Resort 
&  Spa,  you’ll  meet  and  learn 
from  the  finest  leaders  in 
information  technology  today. 
Since  many  who  will  attend 
and  present  will  be 
Computerworld’s  Premier  100 
IT  Leaders  -  Fortune  1000 
IT  executives  honored  by 
Computerworld  as  outstanding 
practitioners  of  leading-edge 
IT  -  you’ll  see  early  adopters 
of  technology  and  business- 
savvy  executives  who  excel 
at  leveraging  strategic 
information  resources. 


CONFERENCE  AGENDA 


Sunday,  June  18, 2000 


12:00pm  -  5:00pm 

Registration 
7:00pm  -  9:30pm 

Pre-Conference  Networking  Reception 


Monday,  June  19, 2000 


8:30am  -  9:00am 

Welcome  and  Opening  Overview 

Maryfran  Johnson,  Editor-in-Chief 
Computerworld 


9:00am  -  9:45am 

Opening  Keynote:  “IT  Leadership  vs.  E-Leadership” 

Charlie  Feld,  E-Leader  and  former  CIO,  Delta  Airlines 
CEO,  The  Feld  Group 


10:00am  -  11:30am 

|  “The  Naked  Truth  About  B2B  E-Commerce" 

Kevin  Fogarty,  Business  Editor 
,  S  i  Computerworld 


Moderator 


Panelists: 

Robert  Schwartz,  VP  &GM 
Panasonic  Corp, 

Kathy  Brittain-White,  CIO  &  EVP 
Cardinal  Health  (cardhaal8r.com) 


Peter  Burrows,  CTO 
ReSiotUntematiQiBl 


John  Keast,  CtO/CTO 
NetworkOit 


Bruce  Carver,  VP  of  Infbimational 


Everybody’s  talking  about  business-to-business  collaboration  as  the 
hottest  of  the  online  trends  in  2000,  But  many  feel  this  emperor  still 
has  no  clothes.  This  panel  will  cut  through  the  hype  surrounding  e- 
marketplaces,  answering  some  critical  questions  on  the  benefits  ver¬ 
sus  the  risks.  Should  your  company  participate  in  someone  else's  B2B 
marketplace  or  create  your  own?  When  and  how  do  you  measure  ROl 
when  you’re  executing  at  Internet  speed?  There  are  multiple  decision 
points  for  entry  into  Web-based  collaboration,  including  infrastructure 
concerns,  business  application  readiness  and  trust  issues  between 
trading  partners.  As  these  new  business  and  organizational  models 
evolve,  what  are  the  key  factors  your  company  must  consider?  Can  it 
really  promote  higher  sales  or  lower  your  production  costs?  IT  leaders 
from  several  industries  will  share  their  successes  and  candidly  dis¬ 
cuss  the  pitfalls  of  B2B  e-commerce  in  this  interactive  session. 


11:30am -12:15pm 

Insider  View:  “Raytheon  Corp.’s  Unfolding 
E-Business  Strategy” 

Eric  Singleton,  Director  of  Global  E-Business 
Raytheon 


12:30pm  -  1:45pm 

Interactive  Luncheon  with  IT  Leaders 


2:00pm  -  3:30pm 

“Enterprise  Security:  Will  Only  the  Paranoid  Survive?” 

Priscilla  Tate,  President 
Technology  Managers  Forum 


Moderator 


Panelists: 

Scott  Chamey 

former  head  of  computer  crime 
Investigations,  U.S.  Department  of 
Justice  and  now  Partner 
PricewaterhouseCoopers 

Allan  Palter 

Columnist,  Computerworld 
and  Research  Director,  SANS 


Tim  Talbot,  VP  of  Technology 
Management,  PHH  Vehicle 
Management  Service 


more  than  doubling  each  year  into  hundreds  of  millions  of  dollars.  Every 
week,  it  seems,  a  new  high-profile  victim  joins  the  list  of  companies  that 
failed  to  protect  themselves  and  their  customers,  Never  have  the  busi¬ 
ness  imperatives  of  secure  commerce  been  so  prominently  in  the  spot¬ 
light,  For  IT  leaders,  the  issues  go  beyond  technical  concerns.  What  are 
your  company's  legal  liabilities  when  customer  data  is  compromised? 
How  do  you  get  past  political  wrangling  over  budget  allocations  for 


your  own  company  --  or  of  your  outsourcers  or  suppliers?  This  session 
will  explore  enterprise  security  in  depth,  drawing  out  examples,  ideas 


3:30pm 


4:15pm 

Afternoon  Keynote:  “Innovation  &  Change” 

Thornton  May,  VP  of  Research 
Cambridge  Technology  Partners 


4:30pm  -  5:30pm 

Premier  Sponsor  Breakout  Sessions  1  and  2 
5:30pm  -  8:30pm 

Expo  Open  and  Reception/Buffet  Dinner 


Tuesday,  June  20, 2000 


8:45am  -  9:00am 

Remarks  and  Day  Two  Overview 
9:00am  -  9:45am 

Keynote 

David  Lord,  CEO 
Toysmart.com 


10:00am  -  11:30am 

“ASPs:  The  Double-Edged  Sword  of  Outsourcing” 

Mark  Hall,  West  Coast  Bureau  Chief 
Computerworld 


Moderator 

Panelists: 

Dick  Hudson,  CIO,  Global  Marine 


John  Voeller,  CKO,  CTO  &SVP 
Black  &  Veatch 


Sateesh  Lete,  President 
tele  Consulting  Group 


Tswi  Gaf,  CIO,  CTO  &  VP  of  Mergers 
and  Acquisitions,  GBS 


Mark  Mathias,  President 
Eureka  Digital 


James  Lubinski,  EVP 
Gallileo  International 


This  latest  trend  is  both  an  option  and  an  obstacle.  As  the  applk 
tion  service  provider  market  grows  beyond  the  small  to  mi 
business  space  to  take  advantage  of  enterprise-class  software, 
leaders  are  considering  ASPs  as  a  serious  tool  in  their  technoti 
strategies.  Vet  will  these  outside  vendors  offer  sufficient  security! 
your  IT  operations?  Can  you  control  point  product  offering 
ASPs?  How  do  you  insure  that  ASPs  deliver  on  service  level 
ments?  Will  today's  high-flyers  crash  to  earth  and  take  your  comp 
ny  with  them?  This  panel  session  will  nail  down  the  critical  sucei 
and  failure  points,  and  answer  the  most  pressing  and  provocaS 
questions  that  ASPs  raise  for  IT  executives. 


11:30am  -  12:15pm 

Featured  Speaker 

Peter  Soivik,  CIO 
Cisco  Systems 


12:30pm  -  2:00pm 

Buffet  Lunch  and  Expo  Open 


2:00pm 


3:30pm 

“Walking  the  E-Customer  Tightrope" 

Julia  King,  Senior  Editor 
Computerworld 


Moderator 

Panelists: 

Cathy  Hotka,  VP 
National  Retail  Federation 


Josegh  Smialowski 
Vice  Chairman 
Fleet  Boston  Financial 


Robert  Rubin.  CIO 
Elf  Atochem  North  America 


Manoj  Tripafi.  CIO  and  Vice  President 
Jamba  Juice 


Technologies  such  as  data  miring  and  customer  relationship  mana 
merit  software  can  put  your  company  right  in  its  customers’  pockets, 
only  anticipating  their  current  needs  but  discovering  new  ones, 
where  does  e-business  cross  over  that  line  between  customer  knov 


tightrope  without  falfing  off?  What  are  fte  best  strategies  tor  leverai 
and  managing  high-impact  business  data  without  alienating  custom 

sus 


tomer  service  differ  from  the  traditional  approach?  This  panel  session 
explore  the  positives  and  the  perils  of  the  customer  connection. 


3:30pm 


Insider  View:  “Taking  Care  of 
E-Customers  at  Autobyte!” 

Ann  Delligatta,  COO 
Autobytel.com 

4:15pm  -  4:45pm 

Premier  Sponsor  Breakout  Session  3 
4:45pm  -  6:30pm 

Expo  Open  and  Reception 


7:00pm 


Premier  100  Awards  Presentation  and  Gaia  Dinner 

Featured  Keynote:  Jim  Yost,  CIO 
Ford  Motor  Company 


Wednesday,  June  21, 2000 


8:45am  -  9:00am 

Remarks  and  Closing  Day  Overview 


9:00am  -  10:30am 

“How  to  Win  the  Hiring  War  Between 
the  ‘Dots’  and  the  ‘Nots’” 

David  Weldon,  Careers  Editor, 
Computerworld 


Moderator 

Panelists: 

Irene  Dec,  VP  of  International 
Investments,  Prudential  Insurance  Co. 


Margaret  Schweer,  HR  Director 
Kraft  Foods 


Robert  Bruce,  CIO,  Allmerica  Financial 


David  Foote,  Managing  Partner 
Foote  Partners  U.C 


Jim  Prevo,  CIO,  Green  Mountain  Coffee 


Fran  Qulttel,  Columnist 
Computerworld 


Matty  traditional  companies  are  reeling  from  the  impact  of  the  c 
com  drainpipe,  as  sexy  little  startups  pull  top  talent  from 
employee  ranks.  Beyond  the  stock  options  and  the  thrill  of  new  v 
fares,  what  are  dot-coms  offering  that  your  company  may  be  ove 
looking?  Are  you  talking  about  career  development,  or  droning  ( 
about  employee  retention?  How  can  you  “steal”  from  your  own  sfe 
in  other  divisions  to  enrich  and  strengthen  the  technology  operatior 
What  kind  of  employee  referral  programs  really  work?  We’il  he; 
from  both  sides  of  the  debate  in  this  lively,  provocative  discussion 
hiring,  head-hunting  and  holding  onto  the  best  IT  people  in  a  sizzllr 
job  market. 


11:15am 

Closing  Keynote:  “Putting  All  the  Pieces  Together: 
The  E-Management  Difference" 

Peter  Keen,  Author,  The  eProcess  Edge,  and  Chairman 
Keen  Education 


REGISTER  TODAY 


Registration  fees  include  entrance  to  Computerworld’s  Premier  100 
IT  Leaders  Conference  and  all  meals  and  networking  receptions. 


Earlybird  Registration  (on  or  before  May  26) 

Pre-Registration  (May  27-June  19) 

$1,295 

$1,495 

Book  Excerpt 


Harnessing  Complexity 


ponent,  called  the  kernel,  is  optimized  for 
speed.  But  the  numerous  other  components 
are  expected  to  honor  a  different  set  of  con¬ 
straints.  There,  interdependence  among  com¬ 
ponents  is  governed  by  strict  principles  of 
modularization  that  severely  limit  side 
effects  that  any  activity  might  have  on 
other  activities.  Speed  is  also  important  out¬ 
side  the  kernel  but  has  to  be  found  within 
the  architectural  constraints  that  give  pri¬ 
macy  to  crash  resistance,  thus  lowering  the 
chances  of  catastrophic  consequences  from 
exploration. 

4  Problems  that  have  looming  disasters. 
This  last  factor  favoring  exploration 
is  not  a  property  of  Linux  open  soft¬ 
ware  development  but  rather  of  the  motiva¬ 
tion  of  some  of  the  developers.  Among  those 
who  have  made  major  contributions  to  Linux 
are  many  who  feared  the  extinction  of  the 
Unix  operating  system  family,  in  which  they 


have  invested  their  exper¬ 
tise.  They  also  feared  the 
rising  hegemony  of  oper¬ 
ating  systems  from  Mi¬ 
crosoft.  For  them,  join¬ 
ing  a  relatively  high-risk, 
exploration-maximizing 
software  project  may  have 
been  an  attractive  alterna¬ 
tive  to  domination  by  what  they  often  call 
“The  Beast  from  Redmond.” 

Taken  together,  our  four  conditions  show 
Linux  to  be  a  development  project  for  which 
it  is  highly  promising  to  strongly  encourage 
variety.  It  does  not  follow  that  open  availabil¬ 
ity  of  source  code  is  a  form  of  magic  that  will 
cause  all  software  projects  to  prosper  as  Linux 
has.  Indeed,  our  analysis  suggests  that  in  order 
for  the  decentralized  generation  of  proposals 
to  be  effective  for  Linux,  several  other  condi¬ 
tions  were  important.  In  particular,  Linux 
development  benefited  from  the  ability  to 


identify  specific  problems, 
make  accurate  copies  of 
the  current  system  with 
only  deliberately  intro¬ 
duced  changes,  evaluate 
the  effectiveness  of  pro¬ 
posed  solutions,  and  cen¬ 
trally  control  the  choice  of 
which  proposals  are  im¬ 
plemented  as  changes  in  the  standard  version. 
It  remains  to  be  seen  just  how  widely  applic¬ 
able  the  decentralized  generation  of  alter¬ 
natives  can  be.  But  open  source  software 
development  clearly  demonstrates  that  even 
very  large  and  highly  structured  systems, 
like  Linux,  can  benefit  from  the  encourage¬ 
ment  of  variety.  00 


Robert  Axelrod  is  a  professor  of  political  science 
and  public  policy  at  the  University  of  Michigan. 
Michael  D.  Cohen  is  a  professor  of  information  and 
public  policy,  also  at  Michigan. 


Don’t  blink. 


Opportunity  can  pass  you  by  in  an  instant.  Let's  make  it  happen.  Together. 

Mergers  &  Acquisitions  Due  Diligence  Senior  Managers 

Logistics,  Operations,  Technology 

Currently  we  are  seeking  driven,  team-oriented  professionals  for  the  New  York  and  Chicago  markets 
to  conduct  and  lead  mergers  and  acquisition  related  assignments.  Duties  will  include  pre-acquisition 
due  diligence,  sell-side  due  diligence,  and  strategic  interaction  with  E&Y  Financial,  Tax,  Benefits,  and 
Insurance  M&A  professionals,  as  well  as  with  private  equity  and  strategic  clients  to  minimize  the  risk 
of  their  intended  investments. 

To  succeed,  you  must  have  8-1 0  years  of  experience  in  the  retail,  distribution,  manufacturing,  health 
care,  banking,  consulting,  or  technology  industries  at  the  CIO,  COO,  General  Manager  or  Director  level. 
Your  strengths  must  include  the  ability  to:  make  detailed  assessments  of  the  technology,  operations, 
logistics,  or  manufacturing  infrastructure  of  a  target  company;  determine  investment  risks  and 
opportunities;  communicate  the  EBITDA  or  cash  flow  impact  of  a  target’s  strengths  and  weaknesses; 
and  work  closely  with  client  executives  to  prepare  investment  model  inputs.  A  strong  client  focus  is 
essential,  as  are  superior  relationship-building,  consulting,  and  verbal  and  written  communication  skills. 
Ernst  &  Young  was  named  one  of  the  1 00  Best  Companies  To  Work  For  in  a  survey  published  by 
FORTUNE*  magazine,  and  offers  a  dynamic  work  environment,  a  competitive  salary  and  a 
comprehensive  benefits  package.  For  immediate  consideration,  please  fax  your  resume  with  salary 
requirements  to:  Ernst  &  Young  LLP,  Dept  KT,  at:  312-879-4211  or  e-mail  kristie.trefzer@ey.com. 
Visit  our  Web  site  at  www.ey.com/us.  Ernst  &  Young  LLP,  an  equal  opportunity  employer,  values  the 
diversity  of  our  work  force  and  the  knowledge  of  our  people. 


=!]  Ernst  &Young 


From  thought  to  finish 


TM 


©2000  Ernst  &  Young  lip 


www.cio.com 


JUNE  1,  2000  CIO  16  3 


* 


Inside 

new  products 

. 166 

revisit 

POS  scanners  ...  170 


predictions 

e-commerce 
software . 1 74 

under 

development 

flat-panel 

screens . 176 


Killer  Viruses  Hit  the  Internet 

A  new  crop  of  unnaturally  born  killers  targets 
networked  computers  by  john  edwards 


Edited,  by  Christopher 
Lindquist.  Send  your 
thoughts  and  ideas  for 
future  columns  to 
et@cio.com. 


USA  GROUP’S  Hamed  Omar  remembers  when 
it  was  relatively  easy  to  protect  enterprise  com¬ 
puters  against  viruses.  “In  the  early  ’90s,  viruses 
spread  from  machine  to  machine  by  ‘sneaker- 
net’ — the  manual  exchange  of  files,”  says  the 


senior  vice  president  of  information  technology 
at  USA  Group,  a  student  loan  guarantor.  “Now, 
viruses  can  spread  in  a  heartbeat  via  the  inter¬ 
net  as  an  e-mail  attachment  and  can  be  a  real 
problem  to  guard  against  and  eliminate.” 


new  viruses. ..better  scanner  data. ..flat  screens. ..e-commerce  software 


164  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  BARRY  FITZGERALD 


We  practice  what 
they  preach. 


Isn't  it  interesting  that  those  companies 
extolling  the  benefits  of  being  an  e-business 
aren't  one  themselves? 


We  a  re.  In  fact,  not  only  did  we  pioneer 
being  direct,  we’ve  become  a  model 
for  how  to  do  business  on  the 


Internet.  Everything  from  being 
integrated  with  suppliers  to 
e-commerce  to  customer  sup¬ 
port-creating  efficiencies  that 
result  in  business  to  business  at  its 


best.  Online. 


Shouldn’t  the  company  that  gives  you 
the  tools  you  need  to  be  an  e-business  be 
an  e-business? 


No  wonder  companies  like  Monster.com, 
iBEAM  and  NaviSite  partner  with  Dell.  And 
use  Dell  PowerEdge@servers  featuring 
Intel® Pentium® III  Xeon™  Processors  to  power 
their  business. 


Dell  knows  how  E  works.  Visit  www.dell.com 


to  learn  more  or  call  1-8 77-How-E-Works 


D^LLO 


pentium®/// 
xeon -7 


Del!  offers  a  complefe  line  of  Intel*-  based  systems.  Expand  your  e-buslness  with 
PowerEdge®  servers  based  on  the  Intel  Pentium®  III  Xeon"  Processor,  including  the 
8450  with  up  to  eight  processors  and  expandable  to  32GB  RAM. 


Intel,  the  Intel  Inside  logo  and  Pentium  are  registered  trademarks,  and  Pentium  ill  Xeon  is  a  trademark  of  Intel  Corporation.  Dell,  PowerEdge.  and  tne  DeH  logo  are  registered  t 
and  How  E  Works  are  trademarks  of  Dell  Computer  Corporation  ©2000  Dell  Computer  Corporation  All  Rigrts  Reserved. 


mmmm 


Much  like  486  processors  and  Win¬ 
dows  3.1,  easily  eradicated  viruses  have 
faded  into  history.  As  the  third  millennium 
dawns,  new  network-aware  viruses  pos¬ 
sess  the  ability  to  wreak  widespread  and 
nearly  instantaneous  damage  on  internet- 
linked  PCs  and  servers. 

Hackers  create  next-generation  viruses 
for  just  one  purpose — destruction — says 


code  ordered  the  infected  PC  to  respond 
automatically  to  incoming  messages  with 
an  attached  file  that,  when  opened,  deleted 
data  in  Microsoft  Word,  Excel,  Power¬ 
Point  and  other  files.  It  was  “purely  evil,” 
says  Bhavnani. 

Jeffrey  Baker,  manager  of  system  ser¬ 
vices  at  Melbourne,  Fla. -based  communi¬ 
cations  equipment  manufacturer  Harris 


“Viruses  are  no  longer  simply  the  minor 
annoyances  they  were  a  few  years  ago. 
Now  they  can  verge  on  the  catastrophic.” 

-Samir  Bhavnani,  research  analyst,  Computer  Economics 


Samir  Bhavnani,  a  research  analyst  at 
Computer  Economics,  a  Carlsbad,  Calif.- 
based  technology  market  research  com¬ 
pany.  “Viruses  are  no  longer  simply  the 
minor  annoyances  they  were  a  few  years 
ago.  Now  they  can  verge  on  the  cata¬ 
strophic.”  Computer  Economics  estimates 
that  virus  attacks  racked  up  more  than 
$12.1  billion  in  damages  to  businesses 
during  1999,  including  loss  of  productiv¬ 
ity  because  of  PC  and  network  downtime. 
“Corporations  cannot  afford  to  play 
Russian  roulette  with  professional  virus 
writers,”  says  Bhavnani. 

Return  to  Sender 

A  new  virus  threat  materialized  last  year 
with  the  arrival  of  the  Melissa  and  Ex- 
plorerZip  viruses.  Melissa  surfaced  in  the 
spring,  sneaking  onto  PCs  as  an  e-mail 
message  with  an  attached  list  of  porno¬ 
graphic  websites.  When  users  opened  the 
file,  the  virus  would  strike.  When  a  user 
attempted  to  send  from  an  infected  ma¬ 
chine  any  Word  document  as  an  e-mail 
attachment  using  Microsoft  Outlook,  the 
message  would  automatically  send  itself  to 
the  first  50  addresses  in  the  client’s  address 
book — bogging  down  networks  and 
servers  with  errant  messages.  ExplorerZip 
arrived  a  few  weeks  after  Melissa  and  was 
even  more  destructive.  This  malicious 


Corp.,  learned  the  hard  way  about  the 
headaches  a  virus  attack  can  inflict  upon 
an  organization.  During  last  year’s  initial 
Melissa  outbreak,  he  spent  a  very  long 
weekend  tending  to  Harris’s  crippled  en¬ 
terprise  e-mail  system. 

Baker  became  aware  of  the  virus  at¬ 
tack  one  Friday  evening  as  he  was  head¬ 
ing  to  dinner  with  several  coworkers. 
“Our  pagers  went  off,  telling  us  that  we 
had  an  important  message  from  [virus 
scanner  vendor]  Network  Associates,” 
he  recalls.  Once  back  at  the  office,  Baker 
discovered  that  all  30  of  Harris’s  mail 
servers  had  been  victimized.  “At  its 
height,  we  had  over  50,000  copies  of  the 
virus  inside  our  Microsoft  Exchange  en¬ 
vironment.”  At  the  time,  Harris  had  no 
virus  protection  installed  on  its  e-mail 
servers,  opting  instead  for  less  secure 
client-based  solutions. 

Baker  and  his  team  detached  the  servers 
from  the  internet  and  spent  frantic  hours 
installing  new  server-based  virus  scanners 
and  clearing  existing  infected  files.  By 
Monday  morning,  he  was  able  to  recon¬ 
nect  the  servers — and  then  he  watched  as 
thousands  of  Melissa-infected  files  tried, 
and  failed,  to  enter  the  company’s  systems. 
“All  in  all,  you  could  say  it  was  a  very 
challenging  experience  and  a  heck  of  an 
interesting  weekend,”  says  Baker. 


Et 


Chasing  Contractors 

Independent  contractors  can  ease 
a  short-term  staffing  crunch  or 
give  you  the  temporary  expertise 
you  need  for  a  special  project.  But 
finding  qualified  contractors  can 
be  a  time-consuming  ordeal.  San 
Rafael,  Calif.-based  icPIanet  Corp. 
tries  to  simplify  the  process  by 
providing  online  access  to  informa¬ 
tion  about  thousands  of  indepen¬ 
dent  contractors  throughout  the 
United  States.  Choose  the  type  of 
contractor  you  need  (software 
development,  systems  administra¬ 
tion,  internet  development  and  so 
on),  then  set  required  availability 
dates,  location,  degree  achieved 
and  other  options.  Start  the 
search,  and  icPIanet  returns  a  list 
of  contractors  that  includes  names, 
years  of  experience  and  a  link  to  a 
more  detailed  resume.  The  site 
also  features  resources  to  help  you 
write  a  contract  and  avoid  IRS 
entanglements  over  who’s  a  con¬ 
tractor  and  who’s  an  employee. 
Best  of  all,  the  service  is  currently 
free  (pricing  will  be  announced 
later).  For  more  information,  visit 
www.icplanet.com. 

Safe  and  Secure 

If  the  security— or  lack  thereof— 
of  your  average  e-mail  message 
keeps  you  up  at  night,  perhaps 
it’s  time  for  a  new  client.  Global 
Market’s  recently  released 
lonlLite  Version  3.1  secure  e-mail 


166  CIO  JUNE  1,  2000  •  www.cio.com 


Problem  is,  your 

timing's  off.  Sweetie. 


TVtfA  lyjicA^.oTtrz.afr(m  AxicjotijcL  aannil. 

If  your  company  is  considering  e-commerce,  e-procurement  or  24/7  status,  network  server  synchronization 
is  essential.  Turn  to  Datum  TymServe,  a  single,  unbiased  time  reference  for  accurate  global  synchronization. 
Without  it,  you  may  find  your  time  has  run  out. 


■  Plug  and  play.  Rack-mountable  units  install  while  your  server  is  running  -  unlike  others. 

■  Redundant  sources.  Use  Global  Positioning  System,  Inter-Range  Instrumentation  Group, 
time  code  or  dial-up  for  time  sources. 

■  Low  maintenance.  Unsurpassed  reliability  leaves  you  free  to  focus  on  other  issues. 

■  Secure  source.  Network  Time  Protocol  traffic  stays  inside  the  firewall  -  unlike  internet  time  sources. 


Melissa  and  ExplorerZip,  along  with 
the  other  network-aware  viruses  that  fol¬ 
lowed  in  their  wake,  were  a  wake-up  call 
to  the  IT  community,  says  Bhavnani.  “Or¬ 
ganizations  started  to  realize  the  severity 
and  the  malicious  intent  of  most  computer 
viruses.”  But  recognizing  the  threat  and 
dealing  with  it  in  a  sensible  manner  are 
two  different  things,  says  Charles  Rut- 
stein,  a  senior  analyst  in  the  e-business 


year-olds  sending  out  stuff.”  Computer 
Economics’s  Bhavnani  agrees,  “This  form 
of  economic  terrorism  is  one  of  the  easi¬ 
est  ways  to  disrupt  a  corporation.” 

Once  you  realize  the  danger,  you  need 
to  act.  A  rapid  response  is  essential  to  stop¬ 
ping  network-aware  viruses  before  they  can 
inflict  widespread  damage,  says  Vincent 
Weafer,  director  of  the  Symantec  AntiVirus 
Research  Center  in  Santa  Monica,  Calif. 


A  rapid  response  is  essential  to  stopping 
network-aware  viruses  before  they  can 
inflict  widespread  damage. 


infrastructure  group  of  Cambridge,  Mass.- 
based  Forrester  Research.  “Despite  the 
increased  awareness,  most  CIOs  only  act 
after  there’s  been  a  widespread  infection,” 
Rutstein  says.  “Then  they  overcompensate 
by  buying  a  tremendous  amount  of  new 
software  and  support.”  The  more  intelli¬ 
gent  approach,  claims  Rutstein,  is  to 
tackle  the  problem  systematically.  “To 
deal  with  viruses  you  must  understand  the 
threat,  design  a  rapid  response,  integrate 
the  response  into  your  existing  security 
infrastructure,  train  your  staff  and  then 
hope  for  the  best.” 

Know  Your  Enemy 

The  first  step  toward  managing  viruses 
is  to  understand  the  people  who  create 
and  unleash  them,  says  Narender  Man- 
galam,  director  of  security  strategy  for 
Islandia,  N.Y.-based  enterprise  manage¬ 
ment  software  vendor  Computer  Asso¬ 
ciates  International.  He  notes  that  many 
CIOs  mistakenly  believe  that  only  atten¬ 
tion-starved  kids  create  viruses.  Although 
not  widely  publicized,  an  increasing  num¬ 
ber  of  virus  attacks  have  been  traced 
back  to  sources  ranging  from  competi¬ 
tors  to  disgruntled  employees  to  interna¬ 
tional  terrorists,  says  Mangalam.  “You 
have  a  lot  of  situations  where  there  is 
malice  involved,  and  it’s  not  merely  16- 


“Vendors  must  quickly  identify  viruses, 
generate  new  updates  and  distribute  them 
to  customers,”  he  says.  “The  customers,  in 
turn,  make  sure  that  the  updates  are  dis¬ 
tributed  across  their  networks.” 

Dodging  the  Bullet 

USA  Group’s  Omar  says  a  rapid  response 
strategy  has  helped  his  company  avoid  a 
major  virus  outbreak.  The  Indianapolis- 
based  company  has  installed  Computer 
Associates’  Unicenter  TNG  Advanced 
AntiVirus  Option  on  each  of  its  PCs. 
Whenever  a  user  signs  onto  a  PC,  the 
software  automatically  installs  the  latest 
antivirus  codes,  then  seeks  out  and  treats 
any  suspicious  files.  But  even  that  level 
of  protection  proved  insufficient,  says 
Omar.  “An  idle  PC  can  receive  an  e-mail 
overnight,  and  until  the  user  signs  on,  the 
virus  can  stay  active  in  the  system  all 
night  long.”  While  the  security  gap  did¬ 
n’t  cause  any  major  problems,  the  poten¬ 
tial  for  a  major  virus  outbreak  worried 
Omar  and  his  staff. 

To  secure  the  breach,  USA  Group  im¬ 
plemented  Computer  Associates’  Uni¬ 
center  TNG  Asset  Management  Option. 
The  software  allows  Omar’s  staff  to  cen¬ 
trally  manage  files  across  all  enterprise 
PCs.  As  soon  as  they  discover  a  virus-con¬ 
taminated  file,  staff  members  treat  it  uni- 


new  ,  , 

products 


system  provides  security  features, 
such  as  automatic  encryption, 
tracking  and  delivery  confirma¬ 
tion,  and  even  a  self-destruct 
mechanism  that  lets  you  destroy 
an  already-sent  message  after 
a  certain  time  or  on  command, 
should  you  fear  the  information 
might  be  compromised.  The  prod¬ 
uct  ranges  from  a  free  “life"  ver¬ 
sion  to  a  $300  “commerce"  edition 
capable  of  dealing  with  enter¬ 
prise-size  volumes  of  e-mail. 

For  more  information,  visit 
www.lonlmail.com. 


The  Search  Is  Over 

If  customers  can’t  find  what  they 
need  on  your  website,  they’ll  look 
elsewhere.  But  some  search  engine 
solutions  can  be  difficult  to  imple¬ 
ment,  while  others  offer  few  fea¬ 
tures.  Searchbutton.com  in 
Mountain  View,  Calif.,  attempts  to 
avoid  both  those  problems. 
According  to  the  company, 
Searchbutton  2.0  lets  you  quickly 
integrate  its  search  engine  into  your 
site  with  little  or  no  programming. 
You  can  then  customize  the  prod¬ 
uct's  look  and  feel  to  match  your 
site,  view  online  activity  reports  to 
see  what  customers  are  looking 
for— and  what  they're  not  finding — 
and  request  reindexing  on  the  fly  to 
guarantee  that  visitors  search  the 
most  current  information.  Pricing 
starts  at  $39.95  a  month.  For  more 
information,  visit  www.searchbutton 
.com  or  call  650  947-8310. 


163  CIO  JUNE  1,  2000  •  www.cio.com 


CIO  Communications,  Inc. 


CIO  100  Symposium  &  Awards'"  is  a 
servicemark  of  CIO  Communications,  Inc. 


Symposium  Moderator: 
Geoff  Moore,  Founder 
and  President 
The  Chasm  Group 

Featured  Presenters: 
Mike  Vance,  Author 
Raise  the  Bar 

Katherine  Hudson,  CEO 
Brady  Corporation 

Scott  Nason,  CIO 
John  Samuel,  VP, 
Interactive  Marketing 
American  Airlines 

John  Puckett 
Chief  Technology  & 
Information  Officer 
toysmart.com 


CIO 


CIO  MAGAZINE'S  ANNUAL  SYMPOSIUM  &  AWARDS 


" One  of  the  best 
Symposium/ conferences 
that  I've  attended.  ” 

Jerry  Rode,  CIO,  Saab  Cars  USA 


Leadership  &  Innovation 
for  the  Future  of  the  Enterprise 


PARTNERS 

Booz*Allen  &  Hamilton 
Candle  Corporation 
Citrix  Systems,  Inc. 

Compaq  Computer  Corporation 
Computer  Associates  International,  Inc. 
EDS 

Gateway  Business 
GTE  Communications  Corporation 
Infosys  Technologies 
Nortel  Networks,  Inc. 

Novell,  Inc. 

PeopleSoft,  Inc. 

Predictive  Systems 
Tivoli  Systems 

Proud  underwriter  of 
the  CIO  1 00  Awards 

(Computer® 

Associates 

Software  that  can  think 


The  CIO  100  Symposium,  an 
annual  program  held  in  conjunc¬ 
tion  with  the  CIO  100  Special 
Issue  of  CIO  Magazine, 
recognizes  Leadership  and 
Innovation  for  the  Future  of  the 
Enterprise ;  and  honors  the  outstand¬ 
ing  achievements  of  100  industry-leading 
organizations. 

This  year  the  CIO  100  award-winning  companies  are  leaders  in  the  rapidly 
changing  and  increasingly  vital  realm  of  customer  service.  By  offering  online 
transactions,  many  leading  companies  are  now  recognizing  the  benefits  of 
understanding  both  customer  and  supplier  needs.  These  efforts  dramatically 
reduce  time  to  market  and  maximize  efficiencies  and  revenue  opportunities. 

Geoff  Moore,  Founder  of  The  Chasm  Group  and  author  of  Living  on  the 
Faultline:  Managing  for  Shareholder  Value  in  the  Age  of  the  Internet ,  returns 
as  our  Symposium  moderator.  Mike  Vance,  Chairman  and  Co-Founder  of  the 
Creative  Thinking  Association,  explores  with  us  how  to  instill  creativity  and 
innovation  into  our  organizations.  Join  over  400  CIOs,  CEOs  and  senior 
executives  at  the  Symposium  to  engage  in  interactive  presentations  and  thought- 
provoking  discussions  with  leading  experts  and  the  CIO  100  honorees. 


CIO  Communications,  Inc. 

To  enroll  or  for  more  information,  call  800  355-0246  or 

CI0 100  Symposium  &  Awards™  is  a  .  .M  ...  ■  .  •  ,  r 

servicemark  of  CIO  Communications,  Inc.  visit  our  Web  site  at  www.ao.com/conferences 


"The  location,  presentation  and  networking  opportunities  were 
fantastic  and  professionally  done  from  start  to  finish. " 


SYMPOSIUM  MODERATOR 


Tony  Stohl,  CFO  &  CIO,  Mental  Health  Corporation 


SYMPOSIUM  PREVIEW 


EXAMINE  Customer 
Relationship  Management 
Success  Stories 

Customer  relationship  manage¬ 
ment  (CRM)  has  become  the 
mantra  for  organizations  that 
want  to  move  past  cost  cutting 
measures  to  achieve  growth, 
increase  market  share  and  build 
customer  loyalty.  The  successful 
CRM  initiative  is  implemented 
through  a  combination  of  busi¬ 
ness  strategy  and  technology. 
This  year's  CIO  1 00  Award 
honorees  share  how  they  have 
developed  an  integrated  view  of 
their  customers  while  achieving 
sustained  competitive  growth. 

EXPLORE  How  to  Create 
Innovative  Environments 

Mike  Vance,  chairman  and 
co-founder  of  the  Creative 
Thinking  Association  of  America, 
provides  methods  for  fostering 
creativity  and  originality  in  our 
organizations. 

INVESTIGATE  New 
Technologies 

Geoff  Moore,  chairman  and 
founder  of  The  Chasm  Group, 
is  among  the  world's  foremost 
high  technology  marketing  gurus 
and  was  recently  named  one  of 
the  Elite  100  leading  the  digital 
revolution.  A  prolific  author,  his 
latest  book,  Living  on  the  Faultline: 
Managing  for  Shareholder  Value  in 
the  Age  of  the  Internet,  provides 
new  models  to  help  analyze  and 
change  current  business  prac¬ 
tices  to  meet  and  surpass  the 
challenges  of  the  marketplace. 


solution  products.  Prior  to 
Brady  Corporation,  Hudson  was 
CIO  of  Kodak.  Named  one  of 
1 2  most  influential  CIOs  of  the 
decade  and  inducted  in  the  CIO 
Hall  of  Fame  in  1 997,  Hudson 
shares  what  it  takes  to  move 
from  CIO  to  CEO. 


EXPERIENCE  The  Famous 
Hotel  del  Coronado 
A  perfect  place  for  a  working 
vacation,  the  del  Coronado 
offers  a  relaxing  setting  to 
reflect  on  lessons  learned  and 
actions  to  take  when  you  get 
back  to  the  office. 


PARTICIPATE  in  Executive 
Mindshare  Sessions 

Led  by  senior  CIO  Editors,  these 
small,  intimate  groups  exchange 
experiences  and  solutions  on  the 
following  topics: 

•  Business  to  Business 
E-Commerce  Success  Stories 

•  Developing  and  Refining  Your 
E-Business  Strategy 


LEARN  How  American 
Airlines  Soars  to  Meet  its 
Customers' Needs 

American  Airlines  has  been  a 
pioneer  in  utilizing  technology 
to  effectively  meet  its  customers' 
needs.  Scott  Nason,  VP  &  CIO  and 
John  Samuel,  VP  of  Interactive 
Marketing  share  how  they 
continually  personalize  their 
services  to  satisfy  customers 
and  increase  revenues. 

NETWORK  With  This  Year's 
CIO  100  Award  Honorees! 

Over  400  CIOs,  CEOs  and  senior 
executives  will  gather  at  this 
year's  CIO  100  Symposium 
to  discuss  the  latest  strategic 
business  and  technology  issues. 

ENJOY  A  PGA  Caliber 
Golf  Course 

On  Sunday  afternoon,  CIO  hosts 
a  golf  tournament  at  the 
Riverwalk  —  San  Diego's  newly 
redesigned  championship  golf 
course.  Why  not  brush  up  on 
your  golf  skills  while  networking 
with  other  conference  attendees? 

UNCOVER  Internet  Security 
Strategies 

John  Puckett,  co-chairman  of 
the  Private  Sector  Council  in 
Washington  D.C.  and  Chief 
Technology  and  Information 
Officer  of  toysmart.com,  addresses 
security  threats.  Are  they  real? 
What  measures  can  be  taken  to 
achieve  an  acceptable  level  of 
security?  Puckett  also  outlines 
how  security  plans  and  policies 
can  be  developed. 


Geoffrey  Moore 
Founder  and  President 
The  Chasm  Group 


FEATURED  PRESENTERS 


Mike  Vance 

Chairman  and  Co-founder 
The  Creative  Thinking  Association  of  America 


Scott  Nason 

Vice  President  and  Chief  Information  Officer 
American  Airlines 


Partners  also  lead  informative 
and  innovative  industry  briefing 
sessions  giving  you  the  latest 
pulse  on  the  information  market. 

DISCOVER  What  It  Takes  to 
Transition  from  CIO  to  CEO 

Katherine  Hudson  is  president 
and  chief  executive  officer  of 
Brady  Corporation,  a  $471 M 
international  manufacturer  of 
identification  and  material 


•  Fostering  Innovation  in  Your 
Organization 

•  Maximizing  the  Customer 
Relationship 

•  Leadership:  New  Economy, 

New  Challenges 

Participants  are  urged  to  bring 
ideas,  questions,  concerns  and 
actual  examples  into  the  sessions. 


JOIN  Us  for  an  Evening 
of  Elegance 

All  participants  are  invited  to 
attend  a  special  black  tie  recep¬ 
tion,  dinner  and  awards  ceremony 
on  Tuesday  evening  recognizing 
this  year's  CIO  100  Award 
honorees.  The  "Oscars"  of  the  IT 
industry,  the  event  features 
champagne,  a  six-course  gourmet 
dinner,  and  presentation  of  the 
CIO  1 00  Award  to  all  honorees. 


John  Samuel 

Vice  President,  Interactive  Marketing 
American  Airlines 


CIO  100  Symposium  and  Awards 5M 
August  13  -  16,  2000 
Hotel  del  Coronado 
San  Diego,  CA 

Enrollment  Application 


Please  attach  business  card  here 
( required ) 


TJNl 


Name: _ Telephone: 

Title: _ Facsimiles 


Company: _ _ 

Address: _ Mail  Stop: _ 

City,  State,  Zip: _ 

E-mail  Address: _ Web  site  URL:. 

Name  as  you  want  it  to  appear  on  your  badge: _ 

□  I  will  bring  a  companion  at  the  cost  of  $350.  Name  of  my  companion: _ 

(Please  note  Companion  Program  details  under  enrollment  fees ) 

What  Is... 

Your  primary  industry? _ 

Your  organization’s  annual  revenues  or  assets? _ 

Your  annual  IT  budget? _ 


Enrollment  Fees: 

O  $2,900  IS  Practitioner/Executive 

Please  make  your  hotel  reservations  immediately  by  calling  the  Hotel  del 
Coronado  at  619  435-0011.  To  receive  the  discounted  rate,  please  mention  that 
you  are  attending  the  CIO  100  Symposium  when  making  your  reservations.  This 
fee  does  not  include  hotel. 


Payment: 

□  Check  enclosed 

□  P.O.  # _ 

(A  complete  purchase  order  must  be  submitted  within 
10  business  days.) 


O  $3,515  Government/Military 

This  fee  includes  your  hotel  for  three  nights.  CIO  will  make  your  hotel  reserva¬ 
tions  for  arrival  Sunday,  August  13  and  departure  Wednesday,  August  16. 
Additional  hotel  reservations  are  your  responsibility. 


□  MC  /  Visa  /  Amex  (circle  one) 
Acct.  #:  _ 


O  $350  Companion  Program 

This  fee  includes  all  scheduled  meals,  receptions  and  entertainment,  companion 
breakfast,  planned  companion  activities  and  the  CIO  100  Awards  Ceremony. 
Companions  are  not  be  eligible  to  participate  in  the  golf  tournament  or  Symposium 
sessions.  Companions  must  be  enrolled  in  this  program  to  attend  any  Symposium 
function. 

O  $10,000  Sales/Marketing/Consulting 

This  fee  applies  if  you  hold  a  sales,  marketing,  business  development  or  consult¬ 
ing  position,  including  executive  management  of  IT  vendor  and  consulting 
companies.  This  enrollment  fee  is  payable  by  company  check  only  and  does  not 
include  three  nights  hotel.  CIO  will  make  the  final  determination  of  this  category. 


Signature: 
Exp.:  _ 


All  fees  must  be  paid  prior  to  the  Symposium,  and  all  cancellations 
and  changes  must  be  made  in  writing.  You  may  cancel  your 
Symposium  attendance  up  to  July  7,  2000  without  penalty.  A  $500 
administration  fee  will  be  imposed  for  cancellations  received 
between  July  8  -  July  28,  2000.  No  refund  or  credit  will  be  given 
for  cancellations  received  on  or  after  July  29,  2000  or  for  no-shows. 
CIO  reserves  the  right  to  limit  attendance  to  practitioners  and 
Partner  organizations. 


To  enroll  or  for  more  information,  call  800  355-0246,  fax  back  to  508  879-7720, 

or  visit  our  Web  site  at  www.cio.com/conferences 


Alien  &  Hamilton 
e  Corporation 
Systems 


<aq 


niter  Associates 


vay  Business 

ommunications 

im 

is  Technologies 
‘I  Networks 

I 

eSoft 

ctive  Systems 
Systems 


HI 


'underwriter  of 
O  100  Awards 

1MPUTER 

SOCIATES 

re  that  can  think, 


for  the  Future  of  the  Enterprise 


{ 

Communications,  Inc. 


AUGUST  13-16,  2000  HOTEL  DEL  CORONADO  SAN  DIEGO,  CALIFORNIA 


rniposium  &  Awards'"  is  a 


To  enroll  or  for  more  information,  call  800  355-0246  or 
visit  our  Web  site  at  www.cio.com/conferences 


REVISIT 

POS  scanners 


Scanners  Gel  Personal 

Point-of-sale  systems  do  more  than  just  track  inventory 

BY  FRED  HAPGOOD 


versally  or  quickly  delete  it  from  every 
company  PC.  “Even  though  we  cannot 
protect  ourselves  100  percent  from  being 
affected,  we  have  a  very  quick  resolution 
time,”  says  Omar. 

Room  for  Improvement 

As  viruses  become  more  sophisticated, 
CIOs  need  to  view  their  protection  strate¬ 
gies  as  coordinated  network  security  ef¬ 
forts.  Sarah  Gordon,  an  IBM  Research 
data  security  analyst,  recommends  deploy¬ 
ing  an  integrated  solution  that  involves 
installing  antivirus  software  on  all  enter¬ 
prise  platforms,  including  servers,  desktops 
and  key  access  points  such  as  internet  gate¬ 
ways.  “You  also  need  intrusions-detection 
software  to  ensure  that  once  there  is  an 
intrusion  you  can  stop  it,”  she  says. 

New  tools  aren’t  the  only  approach, 
however.  Strengthened  staff  training  can 
also  help  reduce  the  risk  of  a  virus  out¬ 
break.  Simple  things,  such  as  not  down¬ 
loading  unnecessary  files  from  the  inter¬ 
net,  not  opening  executable  files  sent  via  e- 
mail  and  not  frequenting  pornographic 
and  other  shady  websites,  can  greatly  re¬ 
duce  an  organization’s  virus  exposure,  says 
Computer  Economics’  Bhavnani. 

Magic  Denied 

A  day  may  come  when  viruses  are  virtu¬ 
ally  unknown,  thanks  to  widespread,  high- 
quality  security  systems.  Computer  Asso¬ 
ciates’  Mangalam  says  he  hopes  that  a 
standards-based  approach  to  virus  secu¬ 
rity,  in  which  the  internet’s  core  structure 
contains  basic  safeguards,  could  make  life 
more  difficult,  if  not  impossible,  for  virus 
authors.  But  CIOs  hoping  for  the  immi¬ 
nent  arrival  of  such  a  magic  bullet  are  set¬ 
ting  themselves  up  for  disappointment. 
“Right  now,  air-tight  security  combined 
with  nonstop  vigilance  offers  the  best — 
and  really  the  only — protection,”  Man¬ 
galam  warns.  EDD 


John  Edwards  is  a  freelance  technology  writer 
based  in  Gilbert,  Ariz.  He  can  be  reached  at 
jedwards@john-edwards.com. 


THE  GOLD  STANDARD  for  personalized 
marketing  was  set  a  hundred  years  ago. 
Back  then  a  storekeeper  knew  his  stock 
by  heart,  kept  all  his  prices  in  his  head  and 
could  direct  a  customer’s  attention  in  real¬ 
time  across  a  succession  of  products  while 
talking  with  the  person  about  his  children, 
the  weather  and  the  harvest.  As  new  retail 
models  have  steadily  taken  us  further  from 
these  old-time  storekeepers,  vendors  have 
looked  back  and  wished  they  could 
reestablish  that  intimate  connection  with 
their  customers. 

In  the  mid-1980s,  several  companies 
claimed  that  they  could  recapture  a  bit  of 
this  relationship  using  point-of-sale  (POS) 
scanner  data.  POS  scanners  were  nothing 
new,  but  most  companies  had  used  the  de¬ 
vices  simply  for  pricing  and  inventory  con¬ 
trol.  The  vendors  claimed  they  could  do 
much  more,  such  as  exploiting  the  scanner 
data  to  track  product  sales  and  market 
share,  identify  trends  and  evaluate  mar¬ 


keting  campaigns.  Although  the  process 
didn’t  promise  to  bring  back  the  old 
days,  it  certainly  was  a  step  in  the  right 
direction. 

In  November  1990  we  ran  an  article 
evaluating  the  technology.  The  story  was 
generally  positive,  agreeing  that  POS  data 
had  a  long  list  of  potential  applications. 
But  there  was  a  shadow  over  the  concept: 
In  retail  environments,  POS  scanners 
could  generate  astronomical  amounts  of 
data — a  million  new  records  per  day  or 
more.  Moving,  storing  and  processing  this 
huge  volume  demanded  technology  un¬ 
available  to  most  companies.  (The  title  of 
the  article,  “Drowning  in  Data,”  reflected 
that  concern.) 

As  a  result,  vendors  pruned  back  the 
applications.  They  transmitted  data  in 
summary  form,  for  instance — though  ana¬ 
lysis  still  took  days  to  complete.  Designers 
were  also  unable  to  combine  data  streams 
or  add  extra  computational  routines,  such 


170  CIO  JUNE  1,  2000  •  www.cio.com 


Dale  and  Doug  Cabel 


Directors  of  WKKm 
Research  and  Development 
WebVision,  Inc.  WtM 


Vision,  WEBtropolis,  ORDERnet,  AUCTIONnct,  PROJECTnct 
and  “E-Business  Services  Provider’  are  also  register 


You've  probably 
heard  about 
our  obsession 
with  redundancy. 


Yes,  you  are  seeing  double. 
When  it  conies  to  setting  the 
standards  for  providing  state-of-the- 
art  hosting  and  collocation  solutions 
WebVision  sets  the  bar.  From  our 
linked  Internet  Data  Centers  right 
down  to  our  staff,  no  one  takes 
redundancy  further! 

We've  spent  years  developing 
our  data  centers,  using  the  most 
advanced,  scalable  and  reliable 
network  architecture  available. 

Leading-edge  hardware  and 
software,  and  an  unsurpassed  service 
and  support  team,  provide  both  high- 
terformance  and  around  the  clock 
tee  of  mind.  Plus,  a  WebVision 
solution  is  cost-effective,  reliable 
and  scalable  to  meet  all  of  your  long¬ 
term  needs. 

Your  ISP/ASP  partner  or  reseller 
solution  couldn't  be  more  clear. 
Contact  us  today! 

mr ' 


55? 


wmmm 


as  better  error  checking.  The  consequence, 
according  to  Frank  Malta  of  IBM’s 
Business  Intelligence  Services,  was  that  for 
all  their  promise,  the  return  on  investment 
for  these  systems  was  marginal  in  practice. 

During  the  last  10  years,  however,  the 
tide  of  computational  power,  called 
Moore’s  Law  (which,  roughly  translated, 
states  that  computing  power  will  double 
every  12  to  18  months),  rose  until  it  lifted 
even  the  worst  POS  resource  hogs  out  of 
the  mud.  About  two  or  three  years  ago, 
recalls  Malcolm  Fowler,  vice  president  at 
Emex  Marketing  Technologies,  POS  scan¬ 
ner  data  applications  crossed  a  subtle 


club-card  number  as  well  as  data  from 
websites,  kiosks  or  call-in  centers.  The  lat¬ 
est  products  also  permit  much  more  elab¬ 
orate  forms  of  analysis.  IBM’s  Malta  claims 
that  that  company  now  uses  artificial 
learning  and  reasoning  algorithms,  such  as 
neural  nets  and  genetic  algorithms,  to 
process  POS  data. 

Bigger  hard  disks  let  users  store  the 
raw  data  without  averaging  or  aggregat¬ 
ing  it,  which  allows  data  mining  down  to 
the  customer  level.  “We  can  ask  ques¬ 
tions  like  ‘Tell  me  the  preferred  colors 
of  our  top  10  customers,”’  says  Tom 
Camps,  vice  president  of  market  strate¬ 


Technology  can  now  look  for  products 
missing  from  one  order  that  tend  to 
appear  in  other,  similar  orders:  milk, 
eggs  and  cereal,  but  no  bacon,  for  instance. 
The  seller  can  immediately  remind  the 
customer  about  the  missing  item. 


point  of  viability,  and  a  wave  of  products 
appeared  to  try  to  deliver  on  the  potential 
of  earlier  claims. 

Ernex,  for  instance,  routinely  builds  sys¬ 
tems  that  can  manipulate  POS  data 
quickly  enough  to  calculate  unique  pro¬ 
motions  while  customers  wait  to  have  their 
orders  rung  up.  For  example,  the  technol¬ 
ogy  can  now  look  for  products  missing 
from  one  order  that  tend  to  appear  in 
other,  similar  orders:  milk,  eggs  and  cereal, 
but  no  bacon,  for  instance.  (The  process 
is  called  “basket  analysis,”  for  obvious  rea¬ 
sons.)  On  the  assumption  that  all  these 
items  belong  together,  the  seller  can  imme¬ 
diately  remind  the  customer  about  the 
missing  item  (“How  about  some  bacon?”) 
and  perhaps  even  offer  a  special  price — all 
calculated  on  the  spot. 

Faster  processors  also  allow  POS  data 
to  integrate  with  other  data  streams,  such 
as  purchase  history  based  on  a  customer 


gies  at  Cognos,  a  manufacturer  of  busi¬ 
ness  intelligence  tools.  “Or  show  me  all 
the  people  who  buy  the  same  things  as 
this  specific  person.”  Meanwhile,  faster 
networks  can  push  the  data  into  more 
departments  and  to  more  business  part¬ 
ners,  such  as  suppliers. 

In  some  cases  this  data  even  doubles 
back  and  revisits  its  origin:  the  customer. 
Image  Info  Software,  based  in  New  York 
City,  sells  POS  analysis  tools  to  clothing 
designer  showrooms.  According  to  Craig 
Schlossberg,  vice  president  of  software  at 
Image  Info,  buyers  need  to  customize  their 
orders  on  such  measures  as  styles,  colors, 
fabrics,  top/bottom  and  woven/knit  ratios. 
Image  Info  aggregates  POS  data  from  sev¬ 
eral  dozen  showrooms  so  that  the  com¬ 
pany’s  clients  can  see  exactly  what  they — 
and  their  competitors — are  buying. 

It’s  enough  to  make  even  that  old-time 
storekeeper  jealous.  ■ 


Et 


Fast  Firewall 

Gigabit  ethernet  holds  tremendous 
promise— the  promise  that  valu¬ 
able  corporate  data  could  be 
stolen  from  your  company  faster 
than  ever  if  you  don't  have  the 
proper  security  systems  in  place. 
To  fill  the  void,  NetScreen 
Technologies  recently  introduced 
the  NetScreen-1000  Gigabit 
Security  System.  The  device  sup¬ 
ports  a  variety  of  security  features, 
including  stateful  packet  inspec¬ 
tion,  TCP/IP  header  parsing  and 
network  address  translation,  as 
well  as  providing  for  gigabit  vir¬ 
tual  private  networking  (VPN). 
According  to  the  company,  a  fully 
configured  system  can  handle 
500,000  concurrent  sessions  and 
25,000  IPSec  tunnels.  NetScreen- 
1000  pricing  starts  at  $109,000. 
For  more  information,  visit 
www.netscreen.com  or  call 
408  330-7800. 

Move  Your  Mail 

Buried  in  e-mail?  You're  not  alone. 
Mail  servers  come  under  more 
strain  today  than  ever  before. 

Part  of  the  problem  is  attach¬ 
ments.  Business-related  or  not, 
millions  of  messages  flow  across 
the  internet  weighed  down  with 
pictures,  documents,  programs, 
music  files  and  more.  Often,  these 
attachments  are  dozens  of  times 
larger  than  the  message  that 
contains  them— bulky  fodder  to  fill 


172  CIO  JUNE  1,  2000  •  www.cio.com 


I 


Name 


Michael  Quinn 


Occupation 

Age 

Household  Income 
Current  Services 

Usage  Profile 


Projected  Lifetime 
Customer  Value 


Tech  Support  Guru 

24 

$45,000 

Gold  Member  Status 
On-Line  Reservations  Log-in 

Airline  Preference:  UAL 
Aisle, Vegetarian  Meal 

Rental  Car  Preference: 

ALM 

2-door,  something  fast 
Hotel  Preference:  HLTN 
King-size,  single 
Non-Smoker 
Business  Traveler 
72%  of  travel  over  1000  miles 
Continent  US  traveler  only 

Vacations  in  Chicago 
to  see  family 

$823,000 


Dynamic 

Customers 

deserve 

Dynamic 

Relationships 

Deliver  dynamic  relationships  with  a  dynamic 
application  -  on  time  and  on  budget.  Chordiant  is 
a  fast,  flexible  application  that  manages  and  drives 
complex  customer  relationships  in  an  integrated 
multi-channel  environment,  including  the  Web! 
Call  us  at  1.888.CHORDIANT. 


Because  Michael  is 

WOrtlicnowmg! 


| 


www.chordiant.com 


_ 


One  Click,  One  Call,  One  Customer. 


Chordiant 

S  O  FTWAR  E,  INC 


PREDICTIONS 

e-commerce  software 

E-Commerce  Software 
Explosion 

GET  READY  to  open  your  wallet.  According  to  a  recent  Forrester  Research  report, 
spending  on  e-commerce  software  will  jump  from  just  over  $3  billion  in  1999  to 
more  than  $14.5  billion  in  2003. 

The  reason?  Rapidly  increasing  pressure  to  quickly  become  players  in  the  “e-con- 
omy"  will  force  companies  to  seek  out  prepackaged  solutions  rather  than  take  the 
time  and  effort  to  code  their  own  software.  The  buying  boom  won’t  take  long  to 
ramp  up  either.  According  to  the  report  by  Analyst  Eric  Schmitt,  IT  spending  on  e- 
commerce  software  will  increase  by  72  percent  this  year  alone  as  companies  devote 
a  larger  part  of  their  IT  budgets  to  software  licensing. 

E-commerce  software  providers  who  want  to  dip  into  that  new  money  may  need 
to  change  their  ways  of  doing  business,  however.  According  to  Forrester,  many  users 
complain  that  current  products  are  difficult  to  integrate  or  fail  to  properly  follow 
standards.  To  remedy  the  situation,  Forrester  predicts  that  software  vendors  will 
divide  into  two  types:  those  who  create  open-standards-based  platforms  and  those 
who  offer  components  that  integrate  into  those  platforms. 

This  new  model  will  also  help  IT  executives  shift  their  focus  from  simply  getting 
sites  up  quickly,  to  creating  long-term,  maintainable  sites  with  enough  built-in 
flexibility  to  adapt  to  changing  requirements— a  critical  feature  in  the  still-nascent 
internet  market.  -Christopher  Lindquist 


new 

products 


server  disks.  Mountain  View, 
Calif.-based  Veritas  Software's 
new  product,  Remote  Storage  for 
Microsoft  Exchange— when  used 
in  conjunction  with  the  compa¬ 
ny’s  Backup  Exec  archiving  tool- 
can  automatically  move  aging 
attachments  to  another  storage 
device,  such  as  a  tape  drive, 
while  still  providing  users  with 
access  to  the  files.  Pricing  starts 
at  $4,995  for  existing  Backup 
Exec  users.  For  more  information, 
visit  www.veritas.com  or  call  650 


335-8000. 


In  the  Cards 


PC  card  readers  for  desktop  com¬ 
puters  are  nothing  new,  but  many 
of  the  devices  are  single-slot, 
external  units  optimized  for  read¬ 
ing  images  from  a  digital  camera. 
Sunnyvale,  Calif.-based  Actiontec 
Technologies’  PC750  Card  Reader 
offers  more  flexibility.  The  device 
mounts  in  a  3.5-inch  drive  bay 
and  connects  to  your  system  via  a 
PCI  card,  ensuring  faster  transfer 
rates  than  external  readers  typi¬ 
cally  do.  The  dual-slot  drive  sup¬ 
ports  PCMCIA  Type  I,  II  and  III 
cards,  letting  you  use  hard  disk 
drives,  Flash  memory  cards,  secu¬ 
rity  cards  and  more.  You  can  also 
add  and  remove  cards  without 
having  to  shut  down  or  reboot  the 
system.  The  reader  retails  for 
$149.95.  For  more  information, 
visit  www.actiontec.com  or  call 
800  797-7001. 


174  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  DAVE  WILLIAMS 


Ah, the 

Internet. 

Pioneering  new  marketing  methods. 
Tapping  into  new  markets. 

Getting  sued  by  millions  of  customers  for  violating  their  privacy. 


Consumers  are  becoming  more  savvy  about  protecting  their  personal  information  online.  It’s  in 
the  best  interest  of  your  business  to  show  them  that  you  share  their  concern.  PrivaSeek’s 
technology  gives  consumers  control  over  their  online  profiles.  And  empowers  them  to  decide  how 
this  information  is  shared.  Empowering  your  business  with  this  technology  allows  you  to  speak 
to  your  customers  in  an  efficient,  permissioned,  one-on-one  approach.  With  several  packages 
available,  incorporating  PrivaSeek’s  technology  into  your  website  is 
virtually  effortless.  You’ll  know  your  customers  better.  And  your 
customers  will  have  greater  confidence  in  you.  www.privaseek.com 


UNDER  DEVELOPMENT 

fiat-panel  screens 


Pint-Size  Power  Supplies 


LAPTOPS,  PDAs  and  other  portable 
computers  continue  to  get  thinner  and 
lighter,  but  a  new  twist  on  old  technology 
may  soon  give  them  a  chance  to  slim  down 
even  more. 

The  electromechanical  transformers 
that  currently  power  flat-panel  displays 
are  big  and  heavy,  says  Kenji  Uchino,  a 
professor  of  electrical  engineering  and 
materials  at  Penn  State  University  and  a 
member  of  the  school’s  materials  research 
laboratory.  The  devices  use  a  pair  of  bulky 
wire  coils  to  increase  low  battery  voltages 
to  the  higher  levels  required  by  the  screens. 


Those  coils  add  weight  and  size  to  porta¬ 
bles,  but  that’s  not  the  only  problem:  The 
units  also  produce  magnetic  fields  that, 
without  shielding,  would  wipe  the  data  off 
floppy  disks  and  hard  drives. 

Uchino  hopes  that  vendors  will  even¬ 
tually  replace  these  electronic  monsters 
with  a  new  type  of  thumbnail-size  ceramic 
piezoelectric  transformer  (about  one-tenth 
the  size  and  weight  of  traditional  trans¬ 
formers)  that  he  recently  developed  with 
fellow  Penn  State  researchers. 

Transformers  are  critical  for  portables 
because  their  flat-panel  screens  require 


Et _ 

more  energy  than  any  other  component. 
While  most  portable  computers  run  on 
12-volt  batteries,  a  transformer  must  pro¬ 
duce  500  volts  to  turn  on  a  screen’s  back¬ 
light  and  then  maintain  a  steady  250  to 
300  volts  to  keep  it  lit. 

In  the  past,  however,  attempts  at  shrink¬ 
ing  transformers  also  reduced  their  effi¬ 
ciency.  But  even  very  small  piezoelectric 
transformers,  which  use  oscillating  ce¬ 
ramic  crystals  to  step  up  voltage,  can  oper¬ 
ate  at  full  efficiency.  The  new  transformers 
offer  more  than  a  90  percent  boost  in  effi¬ 
ciency,  along  with  higher  reliability  and  no 
need  for  shielding,  compared  to  electro¬ 
magnetic  transformers. 

Uchino’s  circular  device  also  marks  an 
improvement  over  rectangular  piezoelec¬ 
tric  transformers,  which  were  widely  used 
in  color  TVs  until  they  were  abandoned 
several  years  ago  because  of  excessive  heat 
generation  and  physical  fragility  problems. 
Uchino’s  version  generates  no  heat  and  is 
much  more  durable:  Its  disklike  shape 
resists  fracturing  at  major  stress  points. 

“Piezoelectric  transformers  are  not  only 
more  efficient,  smaller  and  lighter,  but  they 
are  also  much  less  expensive  to  manufac¬ 
ture  than  conventional  coil-wound  trans¬ 
formers,”  says  Uchino.  The  new  trans¬ 
former  will  sell  for  about  10  to  40  cents, 
although  required  support  circuitry  will 
drive  the  total  manufacturing  cost  to 
approximately  $1  to  $3.  Regardless,  that’s 
a  bargain  compared  with  electromagnetic 
transformers,  which  typically  cost  more 
than  twice  as  much  to  make. 

Penn  State  is  looking  to  license  the 
technology  to  component  vendors  that 
supply  manufacturers  of  notebook  PCs 
and  other  flat-panel-equipped  devices. 
According  to  Uchino,  the  transformers 
could  go  into  production  shortly  after 
any  deal  occurs.  -John  Edwards 


The  new  transformers  offer  more  than  a  90  percent  boost 
in  efficiency  compared  to  electromagnetic  transformers. 


176  CIO  JUNE  1,  2000  •  www.c'io.com 


ILLUSTRATION  BY  GEORGE  SCHILL 


Are  you  spending  more  time 
looking  into  your  network 
than  looking  out  for  your 
business  in  the  marketplace? 

Do  pedestrian  problems  with  your 
LAN  or  WAN  bring  you  to  a 
standstill?  What  about  help 
desk  support?  Or  security?  Don’t 
worry.  We’re  GTE  Communications 
Corporation.  We’re  part  of  one  of 
the  largest,  most  experienced 
communications  companies  in 
the  world.  And  we’re  here  to  help 
you.  Because  we  have  the  products, 
the  services,  and  the  scalability  to 
meet  your  varying  needs  in 
Data,  IP,  and  Voice.  For  your 
broadest  range  of  problems,  CTE 
Communications  has  solutions. 
Solutions  that  can  help  your 
business  be  more  productive,  cost- 
efficient,  and  profitable.  So  you 
can  stand  out  in  even  the  most 
highly  competitive  market. 


GTE  COMMUNICATIONS 
CORPORATION 


IN  THIS  SECTION 


Difference  Engine 

Simson  L.  Garfinkel . 178 

Sound  Off 

Martha  Heller . 182 

Platform 

Tom  Murphy . 186 

Reality  Bytes 

Megan  Santosus . 188 

From  the  Publisher 

Gary  Beach  . 192 


Difference  Engine 

The  Social  Impact  of  Technology 


Private  Matters 

Could  your  organization’s  privacy  practices 
stand  the  scrutiny  of  a  newspaper  expose? 

BY  SIMSON  L.  GARFINKEL 


A  BIOMEDICAL  STARTUP  working  on  an  improved  fertility  test 
orders  a  hundred  vials  of  human  female  blood  from  a  fertility 
lab.  Each  vial  comes  labeled  with  the  fertility  analysis — and, 
unexpectedly,  with  the  name  of  the  woman  who  gave  the 
blood.  Essentially,  it’s  a  list  of  women  who  are  trying  to  become 
pregnant,  and  the  list  includes  two  very  high-profile  names. 
It’s  a  huge  violation  of  medical  privacy,  one  that’s  the  result  of 
a  simple  oversight  at  the  testing  lab. 

A  husband-and-wife  team  is  arrested  for  credit  fraud.  In 
their  house,  investigators  find  countless  credit  cards  embossed 
with  other  people’s  names.  The  couple  is  charged  with  iden¬ 
tity  theft  and  accused  of  charging  more  than  $50,000  worth 


of  merchandise  to  other  people’s  accounts.  No  blame  falls  on 
the  credit  card  companies  that  eagerly  opened  the  fraudulent 
accounts  without  properly  verifying  the  couple’s  true  identity. 

A  computer  enthusiast  buys  a  pair  of  used  PCs  from  a  com¬ 
puter  store.  On  the  first  are  three  years’  worth  of  legal  records 
from  a  local  law  firm.  The  second  includes  a  family’s  financial 
records,  college  application  essays  and  five  years’  worth  of  a 
woman’s  diary. 


178  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  DAVID  GOLDIN 


When  barriers  fall,  we  all  rise. 


t-  9  244 

:  * 

PWwfY'  ..  /rimm  f 

ajar 1  J 

¥  \  :  J 

IS 

Viatel  welcomes  you  to  a  new  world  of  communications. 

A  world  where  new  integration  of  pan-European,  North  American,  trans-Atlantic  and 
metropolitan  high-speed,  fiber-optic  networks  makes  local,  national  and  regional  boundaries 
to  communication  disappear. 

A  world  where  new  networking  technology  shatters  physical  limits  on  the  speed  and 
movement  of  information. 

A  world  where  innovations  —  in  products,  pricing  and  delivery  —  redefine  customer  access 
and  eliminate  constraints  on  usage. 

Viatel’s  new  rules  for  this  new  world  of  communications? 

No  borders.  No  barriers.  No  limits. 

Viatel  from  anywhere  in  Europe  00800.0064.4444 
Viatel  in  the  U.S.  1.800.528.1660 
www.viatel.com 


VIATEL. 

©  2000  Viatel.  Inc. 


Opinion  Difference  Engine 


These  days  it’s  hard  to  pick  up  a  newspaper  and  not  read 
an  article  about  the  ways  computers  are  being  used  to 
triangulate  our  lives  and  attack  our  privacy.  In  Janu¬ 
ary,  the  New  York  Post  described  how  that  city’s  police  depart¬ 
ment  is  using  subway  cards  as  a  way  of  tracking  the  move¬ 
ments  of  criminal  suspects.  USA  Today,  meanwhile,  detailed 
DoubleClick’s  decision  to  combine  anonymous  web  surfing 
profiles  with  individual  names  and  addresses — a  decision  that 
Doubleclick  reversed  only  after  tremendous  public  outcry. 

Americans  are  increasingly  angered  by  the  seeming  inability 
of  business  and  government  to  respect  their  perceived  privacy 
rights.  Indeed,  a  recent  BusinessWeek/Harris  poll  found  that 


57  percent  of  Americans  believe  “the  government  should  pass 
laws  now  for  how  personal  information  can  be  collected  and 
used  on  the  internet.”  But  as  the  three  previous  examples  show, 
privacy  snafus  aren’t  always  the  result  of  an  organization  decid¬ 
ing  to  violate  our  privacy  for  fun  and  profit — nor  are  the  prob¬ 
lems  confined  to  the  internet.  Instead,  many  privacy  violations 
are  simply  the  result  of  careless  information  handling  or  policies. 

Poor  practices  for  handling  personal  information  have  long 
been  a  problem  for  American  businesses  and  government.  One 
of  the  reasons  is  that  they  have  little  formal  guidance  or  experts 
to  whom  they  can  turn  to  when  it  comes  to  techniques  for  prop¬ 
erly  safeguarding  privacy.  That’s  not  the  case  in  other  coun¬ 
tries,  however.  For  example,  after  the  Public  Library  of  Van¬ 
couver  installed  30  closed-circuit  surveillance  cameras  to  deter 
theft  and  vandalism,  the  privacy  commissioner  of  British 
Columbia  made  an  inspection  of  the  premises.  The  commis¬ 
sioner  then  issued  a  report  that  showed  how  the  cameras  could 
be  altered  to  do  a  better  job  of  stopping  theft  while  simultane¬ 
ously  having  less  impact  on  personal  privacy — for  example,  by 
notifying  the  public  that  the  cameras  existed,  rather  than  keep¬ 
ing  their  presence  secret.  (Details  of  the  report  can  be  found  at 
www.oipcbc.org/investigations/reports/invrptl2.html.) 

But  unlike  our  counterparts  in  Canada,  Europe,  Australia 
and  even  Hong  Kong,  Americans  lack  both  the  legislation  that 
would  establish  minimal  privacy  standards  and  a  regulatory 
agency  that  could  advise  businesses  on  acceptable  privacy  prac¬ 
tices.  The  lack  of  such  structures  is  increasingly  causing  prob¬ 
lems  for  American  companies  that  do  business  abroad,  thanks 
to  the  European  Union’s  Data  Protection  Directive,  which  pro¬ 
hibits  companies  from  transferring  personally  identifiable  infor¬ 


mation  from  EU  member  countries  to  jurisdictions  where  that 
information  is  not  treated  with  respect  by  law — jurisdictions 
such  as  the  United  States.  (U.S.  negotiators  are  working  with 
the  Europeans  to  find  some  way  around  the  EU  regulations 
but  no  formal  agreement  is  in  place.) 

Although  the  United  States  has  many  laws  on  the  books 
that  speak  to  the  issue  of  privacy — one  that  gives  Americans  the 
legal  right  to  see  their  credit  records,  for  example,  and  another 
that  prohibits  video  rental  stores  from  releasing  the  names  of 
the  movies  that  you  rent — the  country  lacks  an  overall  scheme 
for  dealing  with  the  issues  of  data  privacy.  Until  such  legislation 
is  drafted  and  passed,  American  businesses  operate  in  an  uncer¬ 
tain  environment.  Like  chemical  factories  in  the 
1960s  that  poisoned  rivers  but  violated  no  laws, 
today  many  businesses  would  earn  the  public’s 
ire  if  an  enterprising  reporter  were  to  merely 
detail  their  handling  of  personal  information. 

So  what’s  an  upstanding  corporation  to 
do?  The  best  way  to  address  these  ques¬ 
tions  is  by  consistently  applying  the 
Code  of  Fair  Information  Practices  and  the  1980  OECD  pri¬ 
vacy  guidelines  (see  www.databasenation.com  for  more  on  the 
guidelines).  Make  sure  that  your  organization  collects  only  the 
personal  information  that  is  necessary  to  deliver  your  product 
or  service — and  make  sure  that  the  information  is  carefully  pro¬ 
tected,  accessible  only  to  those  with  a  need  to  know.  Provide 
a  means  for  consumers  to  view  their  own  files  and  correct 
incorrect  information.  If  you  intend  to  use  customer  informa¬ 
tion  for  research  or  marketing,  be  sure  to  inform  your  cus¬ 
tomers  of  this  intention,  and  give  them  a  way  of  opting  out  of 
your  plans. 

Another  good  strategy  is  to  make  someone  within  your  orga¬ 
nization  responsible  for  privacy  issues.  Most  European  compa¬ 
nies  are  legally  required  to  have  such  an  individual,  but  few 
American  companies  do.  That  person  should  have  a  mandate  to 
analyze  and  change  business  practices,  if  necessary.  Their  posi¬ 
tion  should  be  akin  to  a  director  of  security,  since  security  and 
privacy  go  hand  in  hand. 

Ultimately,  privacy  protection  is  much  more  than  simply 
another  feel-good  public  relations  move.  One  of  the  most  valu¬ 
able  assets  that  organizations  have  is  the  trust  of  their  cus¬ 
tomers  and  constituents.  Being  cavalier  about  privacy  is  one 
of  the  most  effective  ways  for  an  organization  to  tell  the  pub¬ 
lic  to  buzz  off  and  go  elsewhere.  BE] 


Do  you  think  privacy  matters?  Let  us  know  at 
difference@cio.com.  Simson  Garfinkel  is  the  author  of 
Database  Nation:  The  Death  of  Privacy  in  the  21st 
Century  (O’Reilly  &  Assoc.,  2000). 


Many  privacy  violations  are  simply  the  result 
of  careless  information  handling  or  policies. 


1  8  0 


CIO  JUNE  1,  2000  •  www.cio.com 


r. 


While  you’re  driving  your  business  forward,  we’ll 
alert  you  to  the  signals  &  warnings  along  the  way. 


On  the  road  to  your  business  goals,  there 
are  signals  coming  from  every  direction- 
customers,  processes,  financial  results,  and 
your  own  staff. 

The  signals  reveal  whether  you’re  still  on 
course  or  need  to  change  direction.  But 
how  do  you  know  which  business  signals 
to  follow — and  which  to  ignore? 

For  answers,  turn  to  Corporate  Performance 
Management  with  the  SAS^Solution  for 
Balanced  Scorecard.  It  tracks  key  perfor¬ 
mance  indicators,  revealing  how  they’re 
impacting  each  other  and  your  business. 

Sustain  and  improve  shareholder  value  _ 


Align  your  business  around  common  goals 
Optimize  resources  throughout  your  company 
Monitor  the  health  of  your  entire  enterprise 


Visit  us  at  www.sas.com/scorecard  for 

your  free  guide  to  Driving  the  Vision  with 
a  Balanced  Approach. 


Opinion 


Sound  Off 

Taking  Sides  on  Critical  Issues 


Why  Are 
We  Protecting 
the  Software 
Industry? 


BY  MARTHA  HELLER 


SOFTWARE  VENDORS  in  Virginia  must  love  their  legislature.  On  Feb. 
29,  2000,  the  state’s  General  Assembly  gave  final  approval 
to  the  Uniform  Computer  Information  Transaction  Act 
(UCITA),  which  Gov.  Jim  Gilmore,  a  staunch  supporter  of  the 
high-tech  industry,  then  gave  his  blessing. 

UCITA  was  designed  to  provide  uniformity  to  the  myriad 
laws  in  different  states  that  now  govern  the  sale  and  licensing  of 
software  products.  Opponents  of  the  Act,  which  run  the  gamut 
from  consumer  advocacy  groups  to  businesses  that  buy  large 
amounts  of  software,  worry  that  in  addition  to  making  con¬ 
tracts  uniform,  the  legislation  will  give  software  publishers 
greater  legal  clout  to  enforce  their  “shrink-wrap”  licenses, 
licenses  that  are  so  broad  and  unabashedly  protective  that 
many  courts  have  failed  to  support  them.  One  condition  of 
some  agreements,  for  example,  forbids  a  software  user  from 
publishing  a  negative  review  of  the  product,  regardless  of  the 
product’s  shortcomings.  Another  condition  prohibits  a  com¬ 
pany  that  is  acquired  by  or  merges  with  another  company  to 
transfer  the  software  to  the  new  corporate  entity.  Under 
UCITA,  critics  claim,  vendors  that  believe  their  customers  have 


failed  to  follow  these  and  other  conditions,  will  have  legal 
recourse  to  enter  their  customers’  computers  and  literally  shut 
them  down. 

Predictably,  software  manufacturers  like  Microsoft  and 
AOL,  and  high-tech  lobbyists  like  the  Business  Software 
Alliance,  have  been  pushing  hard  for  UCITA,  arguing  that  if  the 
software  industry  is  going  to  continue  to  develop  at  the  pace 
it  has,  manufacturers  need  to  maintain  certain  controls. 

The  software  industry,  UCITA’s  supporters  imply,  needs  pro¬ 
tection  from  those  consumers  who  want  to  use  software  with¬ 
out  paying  for  it,  copy  and  distribute  it  to  their  colleagues,  and 
write  unfair  and  negative  product  reviews. 

Who  are  they  trying  to  kid?  Software  may  already  be  the  sin¬ 
gle  most  powerful  industry  since  Big  Oil  was  made  slightly 
less  big  three  decades  ago.  According  to  a  1999  study  con¬ 
ducted  by  the  BSA,  since  1994,  software  sales  have  grown 


182  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  CHRIS  SHARP 


WWW.segue.com  the  e-business  reliability  experts 


A  Recess  denied. 

— - — . — — — - - - — 

^■i 

Insufficient  resources.  Stock  market  j 

unavailable  this  afternoon.  Please 

try  tomorrow. 

I 

OK 

Opinion 


Sound  Off 


15.4  percent  a  year,  while  the  gross  domestic  product  has 
grown  at  a  rate  of  only  5.4  percent.  The  study  predicted  that  by 
the  end  of  2000,  the  software  industry’s  contribution  to  the 
U.S.  economy  would  be  greater  than  the  contribution  of  any 
other  manufacturing  industry.  In  1997,  the  average  salary  for 
employees  in  software  companies  was  $69,000,  more  than 
twice  that  of  employees  in  any  other  private  industry. 

The  fact  is,  software  is  so  big  and  so  powerful  that  it  can 
make  or  break  a  state’s  economy,  and  politicians  know  it.  If 
AOL,  displeased  with  Virginia’s  high-tech  policy,  were  to  high- 
tail  it  to  Maryland,  Virginia’s  economy  would  suffer.  State  leg¬ 
islatures  are  protecting  software  companies  to  protect  them¬ 
selves,  not  out  of  a  concern  over  the  software  industry. 


Do  software  companies  need  protection? 


Want  to  sound  off  on  this  or  other 
topics?  Join  the  ongoing  debates  at 
com  men  t.  cio.  com. 

We  know  why  politicians  are  passing  legislation  that  pro¬ 
tects  software  companies  at  the  expense  of  individual  and  busi¬ 
ness  end  users.  But  we  don’t  have  to  support  them  in  doing  it. 
This  thread  began  on  March  1,  2000,  and  here  is  a  sampling 
of  the  responses  that  Senior  Web  Editor  Martha  Heller 
received.  You  can  respond  to  her  by  e-mail  at  mheller@cio.com 
or  via  the  web  at  comment.cio.com. 

THE  SOFTWARE  COMPANIES  AS  A  WHOLE  NEED  TO  BE  HELD 
accountable  for  the  code  they  are  selling — before  any  protec¬ 
tions  should  be  granted.  I  would  guess  that  hundreds  of  mil¬ 
lions  of  dollars  are  spent  each  year  to  fix  or  replace  poorly  writ¬ 
ten  and  bug-ridden  software  packages.  It  astounds  me  the  level 
at  which  we,  the  consumer,  put  up  with  bugs,  patches,  ver¬ 
sions  and  upgrades.  I  would  like  the  software  companies  to 
be  required  to  recall  their  software  if  a  certain  percentage  of 
customers  are  negatively  affected  by  its  installation. 

Bret  Richardson 
IT  Manager 
Jore  Corp. 
bretr@jorecorporation.com 

I  DO  NOT  THINK  YOU  ARE  ASKING  THE  RIGHT  QUESTION. 
The  question  should  be,  Why  are  we  passing  legislation  that 
circumvents  free-market  action?  The  software  industry  can  be 
controlled  by  the  action  of  the  free  market.  When  the  software 
market  tried  to  use  widespread  software  protection  devices 
and  utilities,  the  marketplace  stopped  buying  software  from 


those  companies  that  used  them.  In  this  case,  the  same  thing 
will  happen. 

Paul  Lohnes 

Senior  Consultant 
ITC 

phl99@ix.netcom.com 

PIRACY  AND  ABUSE  WILL  NO  MORE  STIFLE  THE  SOFTWARE 
industry  than  it  will  stifle  the  music,  movie  or  book  publish¬ 
ing  industries — all  of  which  have  the  exact  same  problem  with 
unauthorized  copying  and  copyright  violation.  Make  no  mis¬ 
take:  Software  is  no  different  from  an  electronic  copy  of  a 
cookbook.  The  reason  UCITA  is  protecting  software  is  that, 
in  a  democracy,  government  goes  where  it’s  pushed,  and  soft¬ 
ware  companies  can  afford  to  push  constantly;  and  it  is  because 
they  are  rich  that  they  can  get  protection.  For  the  historians 
out  there,  see  the  Louis  B.  Mayer  (MGM)  income  tax  case. 
Congress  passed  a  law  just  for  him,  lowering  his,  and  only  his, 
personal  income  taxes! 

Software  encryption  will  much  more  effectively  protect  soft¬ 
ware  than  any  law,  since  pirates  will  violate  whatever  law  there 
is  anyway.  The  big  issue  to  me  is  that  even  today  software 
comes  with  a  disclaimer  instead  of  a  warranty  (note:  the  media 
are  guaranteed,  the  code  is  not!)  and  under  UCITA  the  user 
has  even  fewer  grounds  to  sue  or  complain  if  the  software  is 
just  a  lot  of  expensive  gobbledygook  code  that  hardly  works. 

It  is  up  to  the  users  of  software  to  stop  UCITA  in  their  home 
state  legislatures  and  to  stop  accepting  junk  software. 

David  P.  Vernon 
Consultant 
CSI  Staffing  Inc. 
dvernon@ibm.net 

MY  COMPANY  HAS  MADE  EVERY  EFFORT  TO  REMAIN 
“pirate  free”  and  has  invested  more  than  $1  million  in  software 
that  works — for  the  most  part.  The  fact  is  software  is  the  work 
of  people  and  therefore  subject  to  human  frailty  and  the  des¬ 
perate  focus  of  the  software  company’s  management. 

When  all  is  said  and  done,  there  is  good  software  and  bad 
software  marketed  under  the  banner  of  “Universal  Cure-All.” 
The  marketing  efforts  of  software  companies  extend  far 
beyond  the  functionality  and  reliability  of  their  products.  As 
purchasers,  we  rely  on  the  claims  of  the  manufacturer.  My  busi¬ 
ness  law  memories  would  have  the  manufacturer — not  the  pur¬ 
chaser — responsible  for  functionality  claims.  Libel  is  only  libel 
if  the  statements  are  untrue.When  you  buy  a  license  it’s  yours. 
Putting  caveats  on  the  sale  or  transfer  of  a  license  is  nonsense. 

Albert  T.  Kruzel 
CIO 

akruzel@hotmail.com 


1  8  4 


CIO  JUNE  1,  2000  •  www.cio.com 


-877-66  2  -  5540  WWW.OSPREYUb.CO^ 

2000.  Osprey  Systems.  Inc  All  nqhls  reserved.  Osprey  and  the  Osprey  lopo  are  trademarks  of  Osprey  Systems.  Inc  Other  company  and  product  names  contained  herein  are  trademarks  ol  Ihou  respective  companies 


Opinion 


Platform 

Experience  Counts 


Meeting  of 
the  Minds 


BY  TOM  MURPHY 

IN  THIS  FAST-PACED  world  in  which  technology  executives  are 
supposed  to  make  wise  and  lasting  decisions  for  the  good  of 
our  customers  and  shareholders,  we  must  use  every  means 
available  to  ensure  our  companies’  success.  We  are  under  pres¬ 
sure  from  many  different  angles,  from  recruiting  and  retention 
to  keeping  up  with  changing  technologies.  One  means  that  I 
have  used  to  help  in  this  daily  battle  is  vendor  review  sessions. 

The  cruise  industry  is  a  small  one  by  any  relative  standard, 
and  there  are  many  complexities  that  go  along  with  operating 
the  shoreside  and  shipboard  environments.  The  better  our  ven¬ 
dors  understand  our  business  and  the  environment  we  oper¬ 
ate  in,  the  better  they  are  at  shaping  solutions  for  us. 

If  you  are  like  me,  your  vendors  fit  one  of  three  general  cat¬ 
egories:  one,  close  enough  to  be  considered  a  friend;  two,  a  nec¬ 
essary  evil;  or  three,  scum  of  the  earth.  Regardless  of  which 
category  they  fall  into,  vendors  are  important  allies  in  my  quest 
to  stay  up  to  speed  and  to  influence  the  direction  of  technol¬ 
ogy.  I  have  always  made  it  a  point  to  treat  my  vendors  with 
respect,  to  be  honest  and  candid,  and  to  dissuade  them  from 
quixotic  attempts  to  win  my  business  when  it  is  not  possible. 


I  visit  vendor  sites  when  my  schedule  allows  to  see  current  and 
future  developments,  and  I  encourage  my  staff  to  do  the  same. 

Several  months  ago  I  started  holding  vendor  review  ses¬ 
sions,  and  this  has  had  a  dramatic  effect  on  the  relationship 
between  my  company  and  my  vendors.  The  days  are  two-way 
information  sharing  opportunities.  I  ask  that  the  vendors  re¬ 
frain  from  sales  pitches  and  concentrate  instead  on  under¬ 
standing  my  business  and  my  company’s  technology  needs.  The 
first  part  of  the  day  is  spent  reviewing  my  company’s  six-  and 
12-month  challenges,  and  then  we  talk  about  the  strategic 
vision  for  the  next  36  months.  Our  discussions  focus  as  much 
on  business  issues  as  on  technology.  We  then  turn  the  floor  over 
to  the  vendor.  The  vendor  is  encouraged  to  focus  the  presen¬ 
tation  based  on  what  has  been  discussed  in  the  morning.  The 
benefit?  Virtual  elimination  of  prepared,  canned  presentations. 

I  invite  everyone  in  IT  to  attend  the  sessions,  and  the  atten¬ 
dees  vary  based  on  the  vendor.  We  prepare  by  outlining  the  key 
issues  and  strategies  and  e-mailing  them  to  the  vendors  ahead 
of  time.  I  tell  the  vendors  who  will  be  in  the  audience  and  encour¬ 
age  them  to  bring  the  right  people.  The  sales  guy  is  always  going 
to  show  up.  That’s  fine.  But  the  right  engineer,  the  right  tech¬ 
nologist,  the  right  strategist  must  also  be  present.  This  is  not  a 
glad-handing  session.  I  don’t  care  about  the  titles  of  the  people 
who  show  up  on  the  vendor  side,  as  long  as  they  are  able  to  com¬ 
municate  and  participate  actively  and  effectively. 

I  avoid  the  temptation  to  put  competitive  vendors  on  stage 
together,  regardless  of  the  fun  such  a  fireworks  display  would 
be.  I  do  select  complementary  vendors  and  vendors  that  have 
alliances  or  partnerships  to  participate  together.  This  adds  to 
the  brainstorming  attributes  of  the  meetings. 

So  far,  we’ve  had  five  of  these  meetings  and  are  averaging 
one  a  month.  We  hope  to  make  them  more  frequent  but  time 
constraints  make  that  difficult.  Does  it  always  work  flawlessly? 
Of  course  not.  But  it  works  well  most  of  the  time,  and  as  my 
key  vendors  adapt  to  this  way  of  working  cooperatively  they 
get  better  at  the  process.  The  ones  that  don’t  get  it  and  keep  try¬ 
ing  to  sell  are  simply  stopped  and  the  meeting  is  adjourned. 
One  time  and  they  usually  get  the  message.  Two  times  and  the 
vendor  does  not  get  another  chance.  I’ve  yet  to  have  one  make 
the  mistake  twice.  QI3 


Looking  for  a  platform  for  your  ideas?  Let  us  know  at  platform@cio.com. 
Tom  Murphy  is  CIO  of  Royal  Caribbean  Cruises  in  Miami. 


18  6 


CIO  JUNE  1,  2000  •  www.cio.com 


DIGEX  is  the  leader  in  managed  Web 
and  application  hosting.  Sun  Microsystems 
is  the  leader  in  the  net  economy. 

What  is  SunToneSM  certification?  The  symbol 
of  high  quality  outsourced  services 
sponsored  by  Sun  Microsystems.  It’s  their 
way  of  telling  IT  professionals  that  Digex 
knows  its  stuff. 

Sun  evaluated  our  systems  architecture, 
scrutinized  our  technical  competency, 
analyzed  our  service  level  agreements 
and  assessed  our  physical  and  intellectual 
security  measures. 

The  distinction  of  being  the  first  SunTone 
Certified  solution  provider  underscores 
□  igex’s  leadership  in  the  hosting  industry 
and  our  dedication  to  delivering  the  best 
overall  Web  performance  under  the  sun. 


NE 


s 


LUTION 
OVIDER. 


j 


www.digex.com/SunTone  1.877.593.4439 


©2000  Digex.  Inc.  All  trademarks,  tradenames  and  service  marks  mentioned  or  used  belong  to  their  respective  owners.  All  rights  rf  erved. 


Opinion 


Reality  Bytes 

A  Cold  Look  at  Hot  Trends 


Real-Time 

Angst 

Too  much  access  to  information  can  make 
even  the  sanest  person  a  little  twitchy 

BY  MEGAN  SANTOSUS 

THE  INTERNET  has  garnered  a  lot  of  ink  for  its  ability  to  empower 
the  lowly  individual.  Whether  it’s  haggling  for  the  best  price 
on  a  2000  BMW  Z3  or  hunting  down  a  first  edition  of  The 
Grapes  of  Wrath,  the  internet  can  put  people  smack  in  the  mid¬ 
dle  of  transactions  that  were  formerly  handled  by  specialized 
professionals. 

But  there’s  a  downside  to  this  newfound  power.  Now  that 
we  have  the  ability  to  check  stock  portfolios,  monitor  every 
caprice  of  online  auctions  and  get  up-to-the-minute  sports 
scores,  many  of  us  are  becoming  obsessive  control  freaks.  We 
agonize  over  every  blip  in  the  market,  compulsively  check  eBay 
to  make  sure  we’re  not  missing  out  on  a  good  deal  and  furtively 
monitor  the  goings-on  at  Mercata  in  the  hope  of  saving  a  few 
bucks.  We  may  indeed  be  more  informed  and  enjoy  more 
power  in  transactions,  but  at  the  same  time  we’re  losing  control 
of  our  lives. 

The  result  is  frustration,  anxiety,  even  a  sense  of  nagging 
despair.  I  know.  I’ve  experienced  these  feelings  firsthand.  There 
was  a  time  not  too  long  ago  when  I  was  satisfied  with  the 
monthly  statements  I  received  from  my  investment  company. 


Although  the  information  was  already  a  week  out  of  date  by 
the  time  the  statements  appeared  in  my  mailbox,  I  didn’t  care. 
I  knew  I  could  check  the  value  of  my  account  daily  by  using  a 
Touch-Tone  service,  but  I  didn’t  indulge  myself  much.  The  peri¬ 
odic  statements  seemed  to  reinforce  the  idea  of  investing  for 
the  long  haul.  I  filed  them  away  in  loose-leaf  folders  that  slowly 
took  over  a  shelf  in  a  bookcase. 

Then  came  the  internet.  My  investment  company — let’s  call 
it  Loyalty  Investments — set  up  a  website  featuring  online 
trades,  daily  closing  prices  and  more  fundamental  informa¬ 
tion  than  even  Warren  Buffet  could  want.  I  created  a  portfolio 
page  that  kept  a  running  total  of  my  gains  and  losses  for  both 
my  mutual  fund  investments  and  individual  stocks  I  own. 
(When  I  upgraded  to  a  new  version  of  Netscape,  I  was 
delighted  to  see  the  gains  and  losses  appear  in  green  and  red, 
respectively.)  Although  I  was  still  in  the  market  long-term,  I 


188  CIO  JUNE  1,  2000  •  www.cio.com 


ILLUSTRATION  BY  DANIEL  BAXTER 


Spine-tingling 

suspense... 

Shoot  outs... 

Startling 

revelations... 


Jacob  Javits 
Convention  Center, 
New  York  City 

Exhibits: 

June  27-29,  2000 

Conference: 

June  26-29,  2000 

Use  source  code  M2AD 
when  registering 


I INFORMATIONWEEK 

Flagship  Sponsor  of  the  PC  EXPO  Conference  Program 


V  ;s,  WE  ARE  TALKING 
.  IBOUT  A  TRADE  SHOW 

HERE. 


Doesn't  sound  like  the  PC  EXPO  of  last  year,  does  it?  Well,  it's"' 
not.  It's  a  new  event  that's  as  fast  as  the  pace  of  today's 
economy.  And  if  you  sit  still  for  too  long,  you'll  be  missing  out 
on  all  the  action. 

Get  started  with  a  customized  itinerary  that  moves  you 
toward  your  solutions  at  lightning  speed.  Delve  into  the 
future  of  handheld  devices.  Submit  your  RFPs,  and  be  part  of 
a  live  forum  where  leading  vendors  propose  their  solutions  to 
real  problems. 

Listen  and  learn  as  industry  leaders  shoot-it-out  in  head-to-head  debates.  Get  going  on  your  SANS 
GIAC  Windows  Security  Certification.  Beef  up  your  networking  acumen  at  Novell's  BrainShare  On  Tour. 
Check  out  our  new  expanded  conference  program  with  special  sessions  for  the  Channel,  small  business, 
and  IT  executives.  It's  all  coming  to  PC  EXPO  this  year  and  in  the  years  to  come.  And  if  you're  ready  for 
an  event  that  can  offer  strategies,  solutions — and  more  than  a  few  surprises — you'll  be  coming,  too. 

Act  fast  and  register  early.  Go  to  www.pcexpo.com  to  get  on  board — and  get  the  lowdown  on  all  of  the 
new  developments  you  can  expect  to  see,  hear  and  do  at  PC  EXPO  this  year. 


REGISTER  TODAY  AT:  wvwif.pcexpo.com 


©  2000  CMP  Media  Inc.  All  rights  reserved.  PC  EXPO  is  a  trademark  of  CMP  Media  Inc.  All  other  trademarks  are  property  of  their  respective  owners. 


IT  for  Business 


Opinion  I  Reality  Bytes 


experienced  a  visceral  thrill  checking  my  net  worth  a  couple 
of  times  a  day. 

It  wasn’t  long  before  the  couple  of  times  a  day  became  more 
and  more  frequent.  On  particularly  volatile  trading  days  (and 
we  know  how  often  those  occur  lately),  I’d  keep  my  portfolio 
page  on  my  screen  and  hit  the  reload  button  every  half  hour 
or  so.  If  I  saw  too  much  red,  I’d  walk  glumly  around  the  office 
in  a  semi-catatonic  state  as  if  I  had  just  squandered  my  life 
savings  playing  the  slots  at  Foxwoods  Casino.  If  a  whole  lot 
of  green  appeared,  I’d  entertain  thoughts  of  quitting  my  job 
to  spend  my  days  trying  to  get  my  golf  handicap  significantly 
below  my  age. 


useless  if  we  can’t  act  on  it  when  we  want  to. 


control,  I  felt  lost,  overwhelmed  and  more  than  a  tad  de¬ 
pressed.  I’m  not  alone  in  feeling  disenfranchised.  As  we  all 
become  accustomed  to  incessantly  keeping  up  with  the  vagaries 
of  the  stock  market,  auction  sites  or  any  other  internet  venue 
where  information  changes  by  the  second,  we  invariably  feel 
as  if  the  very  ground  is  shifting  beneath  our  feet.  In  the  end, 
the  up-to-the-minute  information  is  useless  if  we  can’t  act  on 
it  when  we  want  to. 

The  obsession  with  staying  informed  isn’t  just  bad  for  indi¬ 
viduals’  psyches.  It’s  bad  for  the  companies  that  inevitably 
can’t  satisfy  our  quest  for  instant  gratification.  The  day  after  my 
trading  effort  was  thwarted,  I  got  a  solicitation  in  the  regular 

mail  from  my  investment  company.  On 
the  envelope  was  the  marketers’  ques- 

...  .  t  a.  .  tion:  “What  do  134,248  Loyalty  in- 

In  the  end,  the  up-to-the-minute  information  is 

vestors  have  in  common?”  My  sardonic 
answer:  They  all  must  be  trying  to  access 
the  Touch-Tone  trading  system  at  the 
same  time. 

Needless  to  say,  the  whole  experience 
didn’t  instill  any  confidence  that  Loyalty  cared  about  me  as  a 
customer  and  was  willing  to  deliver  on  its  promise  to  instant 
access.  While  companies  have  always  made  gaffes,  now  they 
commit  them  on  the  internet  in  full  view  of  customers  who 
can  have  emotional,  even  irrational  reactions.  If  I  were  speaking 
to  a  Loyalty  broker  who  couldn’t  execute  a  trade  on  my  behalf 
in  a  timely  manner,  I  might  still  be  angry,  but  I  wouldn’t  feel 
despondent.  But  because  the  technical  tools  promised  to  me 
wouldn’t  allow  me  to  make  the  trade  I  wanted  when  I  wanted, 
my  ensuing  sense  of  powerlessness  made  me  a  prime  candi¬ 
date  for  therapy. 

As  companies  rush  to  offer  services  via  the  internet,  they 
should  be  prepared  to  deal  with  the  psychological  ramifications 
of  the  medium.  Customers  will  become  enthralled  with  the  self- 
service  model  and  come  to  depend  on  the  internet  as  if  it  were 
a  lifeline. 

As  for  me,  I’ve  made  significant  progress  since  January.  I 
no  longer  check  my  stocks  daily,  I  log  on  to  the  local  news  site 
only  once  each  morning,  and  I  never  check  my  favorite  online 
bookstore  for  current  sales.  I  suppose  I’m  one  of  the  lucky  ones, 
because  I’ve  come  to  terms  with  my  limitations  as  far  as  the 
internet  goes. 

I  no  longer  have  to  know  about  things  simply  because 
they’re  a  click  away.  I  learned  from  personal  experience  that 
sometimes  ignorance  can  be  bliss.  Or  at  least 
good  for  your  mental  health.  E0 

Although  she  no  longer  checks  her  inbox  50  times  a 
day,  you  can  e-mail  Senior  Editor  Megan  Santosus  at 
santosus@cio.com. 


Keeping  one  eye  always  on  the  stock  market  started  to  taint 
me.  When  a  colleague  attended  a  conference  where  Alan 
Greenspan  was  speaking,  I  didn’t  tell  her  to  have  a  good  time 
and  come  back  with  lots  of  story  ideas.  In  an  e-mail  tinged  with 
desperation,  I  begged  her  to  call  me  ASAP  if  the  Fed  Chief 
made  even  the  slightest  hint  about  raising  rates. 

And  this  bipolar  behavior  flourished  during  a  time  when  I 
had  no  intention  of  selling  anything. 

When  I  did  decide  to  sell  about  25  percent  of  my  holdings 
for  a  down  payment  on  a  house,  any  semblance  of  emotional 
stability  I  had  quickly  evaporated.  I  waited  until  the  end  of 
January  to  make  my  move,  so  the  IRS  wouldn’t  ambush  me 
with  a  hefty  capital  gains  tax  bill.  I  checked  my  portfolio  more 
than  a  dozen  times  a  day  for  two  weeks  or  so,  then  I  deter¬ 
mined  the  time  had  come.  It  wasn’t  as  if  Jupiter  finally  aligned 
with  Mars;  I  just  couldn’t  take  watching  the  market  fluctuate 
any  longer. 

Other  people  must  have  had  the  same  response.  By  1 1  a.m. 
on  the  day  in  question,  the  Dow  Jones  was  well  on  its  way  to 
posting  a  three-digit  upswing.  I  dialed  Loyalty’s  800-number 
to  make  a  quick  trade  using  the  Touch-Tone  system,  and  I  was 
absolutely  flabbergasted.  I  couldn’t  access  the  system  to  make 
a  trade,  and  following  a  cursory  message  to  try  the  website,  I 
was  summarily  disconnected.  But  with  the  collective  pulse  of 
greed  sweeping  individual  investors  looking  to  cash  in  on  the 
market’s  latest  mood  swing,  I  couldn’t  trade  online  either.  The 
sense  of  panic  I  felt  was  enough  to  make  the  thought  of  lunch 
out  of  the  question.  I  sold  the  next  day,  when — true  to  form — 
the  market  gave  back  its  gains. 

So  much  for  the  power  of  the  individual.  Instead  of  feeling  in 


1  9  0 


CIO  JUNE  1,  2000  •  www.cio.com 


EXPERIENCE 


Imagine  a  perfect  e-world. 


For  twenty-five  years,  SAGA™  has  helped 
build  the  enterprises  of  the  world’s  largest  organizations. 
And  now,  an  enterprise-class  solution 
to  connect  legacy  and  packaged  applications  with  the  web. 
True  e-business  integration. 

It’s  a  dream  come  true.  Sagavista™ 

sagavista 

Enabling  the  E-conomy.™ 


Copyright  ©  SAGA  SOFTWARE,  Inc.,  2000.  All  rights  reserved. 

SAGA,  Sagavista,  the  Sagavista  logo,  the  SAGA  logo,  F.Y.I.  sprite,  Free  Your  Information  and  Enabling  the  E-conomy 
are  either  registered  trademarks  or  trademarks  of  SAGA  SOFTWARE,  Inc.  in  the  United  States  and/or  other  countries. 
Certain  product  and  company  names  may  be  trademarks,  service  marks  or  trade  names  of  their  respective  owners. 
Certain  products,  programs  and  services  are  subject  to  availability. 


www.  sagasoftware .  com 


free  your  information.  ( 


Opinion 


From  the  Publisher 

gbeach@cio.com 


Reading  Is 
Fundamental 

THERE’S  A  LOT  of  talk  about  the  old  economy,  the  new  economy, 
the  knowledge  economy,  the  digital  economy. 

And  to  this  list  I  would  like  to  add  another:  the  people 
economy.  Because  what  all  economies  are  based  on  is  people. 
People  who  make  stuff  and  people  who  buy  stuff.  Nothing 
more.  Nothing  less. 

The  importance  of  people  was  made  abundantly  clear  at 
the  recent  CIO  Perspectives  Conference  I  attended  in  Naples, 
Fla.  Yes,  business  alignment  with  technology  is  still  key,  but  to 
implement  that  alignment  CIOs  need  people.  And  right  now 
major  corporations  in  America  continue  to  face  a  huge  IT  job 
opening  gap. 

According  to  the  CIO  KnowPulse  poll  conducted  at  the 
conference,  12  percent  to  15  percent  of  IT  jobs  in  America 
are  unfilled.  This  number  is  in  line  with  the  recent  Informa¬ 
tion  Technology  Association  of  America’s  report  that  claims 
one  in  every  12  IT  jobs  is  vacant.  Incredibly,  the  association 
further  reports,  846,328  of  the  1.6  million  new  IT  jobs  will 
likely  go  unfilled  in  the  coming  12  months.  That’s  50  percent, 
folks.  How  long  can  this  go  on  without  dramatically  impact¬ 
ing  our  economy  or,  more  immediate,  your  business?  The 
people  gap  is  not  new.  We’ve  known  about  it  for  three  years. 
But  what  is  our  industry  doing  about  it? 

Congress  is  giving  lip  service  by  raising  the  cap  on  H-1B 
visas,  a  program  that  allows  foreign  national  workers  to 
reside  in  the  United  States.  Allowing  200,000  foreign  IT 
workers  into  America  each  year  solves  nothing.  The  program 


is  shortsighted  and  is  akin  to  putting  a  Band-Aid  on  a  cut  that 
needs  stitches.  Moreover,  it  doesn’t  address  the  root  cause  of 
the  IT  skills  gap:  The  education  system  in  our  country  is  out 
of  sync  with  producing  skilled  technology  workers. 

The  higher  education  system  desperately  needs  more 
adjunct  professors  like  the  readers  of  CIO  to  immediately 
improve  the  quality  of  IT  education  at  the  college  and  gradu¬ 
ate  level.  But  that  too  is  a  tactical,  short-term  remedy. 

What  we  really  need  is  systemic  change  in  how  we  educate 
Americans.  There  has  been  a  lot  of  talk  lately  about  the 
“digital  divide,”  the  invisible  wall  separating  the  computer 
haves  from  the  computer  have-nots.  Yes,  there  is  a  divide  in 
America,  but  it  has  nothing  to  do  with  one’s  ability  to  com¬ 
pute;  in  reality,  it  has  everything  to  do  with  one’s  education 
level. 

Study  after  study  shows  the  higher  the  level  of  education 
people  achieve,  the  more  likely  they  will  have  the  technology 
skills  needed  in  the  workplace.  I  recently  had  the  opportu¬ 
nity  to  listen  to  U.S.  Secretary  of  the  Treasury  Lawrence 
Summers  speak  on  the  new  economy.  He  claimed  literacy 
was  job  No.  1. 

I  think  he  is  right.  If  CIOs  really  want  to  pitch  in  and  help 
alleviate  the  IT  skills  shortage  over  the  long  term,  they  would 
be  wise  to  look  around  and  suggest  ways  their  companies  can 
help  more  Americans  discover  the  power  of  reading. 

The  people  economy  in  America,  and  the  IT  skills  shortage 
issue,  would  be  better  served  if  we  collectively  taught  200,000 
Americans  to  read  each  year  rather  than  importing  200,000 
foreign  nationals. 

Do  you  have  ideas  on  what  we  should  do?  Send  e-mail  to 
gbeach@cio.com. 


1  9  2 


CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  WEBB  CHAPPELL 


COMPUTERS 
CHANGED  THE  WORLD. 

FINALLY, 

THE  FAVOR  IS  RETURNED. 


MEET  NETVISTA. 


. 


pentium®/// 


Introducing  the  first  IBM  NetVista  desktop:  the  x40 

It’s  what  happens  when  several  good  ideas  come  together.  And  a  few  old. 
complicated  ones  get  the  axe. 


The  result  is  a  powerful  little  charmer  that’s  75%  less  desk-hungry  than  traditional  desktop  pc’s  -  a  nice 
complement  to  a  machine  that  was  engineered  to  be  internet-ready,  human-friendly,  and  refreshingly  simple. 
The  NetVista  x40.  The  first  page  of  the  next  chapter  of  personal  computing. 


THE  IBM  NETVISTAx40  DESKTOP 
AVAILABLE  AT  IBM.COM 


An  integrated  15"  flat-panel  monitor  and  retractable  cd  and  floppy  drives  allow 
for  the  desk-saving  size. 

Five  simple  USB  ports  (and  no  confusing  old  ones)  make  plugging  in  anything 
from  printers  to  scanners  to  Palm  Pilots  almost  automatic. 

Low-profile  PCI  expansion  slots  let  you  expand  as  necessary. 

Preinstalled  ethernet  and  options  like  ADSL  modems  and  wireless  networking 
technologies  make  connecting  to  any  network  safe,  fast  and  easy. 

The  NetVista  x40  is  available  at  800  426  7255  or  ibm.com 

64-512mb  sdram  /  lO^Ogb1  hdd  /  cdrom  / 15"  TFT  screen  tnnlc 

Intel  Pentium  III  processor  up  to  667mhz2/  $1899-$22993  vS™  LUUAb 


pentium®/// 


'gb  equals  one  billion  bytes  when  referring  to  storage  capacity;  accessible  capacity  may  be  less.  2mhz  only  measures  microprocessor  internal  clock  speed;  many  factors  affect  application 
performance.  Estimated  reseller  price  to  end  users  model  6643-13U.  Actual  reseller  prices  may  vary.  PCs  referenced  in  this  ad  include  an  operating  system.  NetVista  and  IBM  product  names  are 
registered  trademarks  of  International  Business  Machines  Corp.  Other  company,  product  and  service  names  may  be  trademarks  or  service  marks  of  others.  Intel,  the  Intel  Inside  logo  and  Pentium 
are  registered  trademarks  of  Intel  Corp.  ©2000  IBM  Corp.  All  rights  reserved. 


CIO  Communications  Inc. 

©  CIO  Communications  Inc. 


CIO  SALES  OFFICES 

President  &  CEO  Joseph  L.  Levy  •  508  935-4601 
Publisher  Gary  J.  Beach  •  508  935-4202 

Executive  VP  Sales/Custom  Publishing 

Ellen  Romanow  •  508  935-4796 

Sales  Operations  Associate  Kim  Harris 

East  Coast 

Senior  VP  Sales/East  Michael  J.  Masters 
973  244-5500,  ext.  21 

VP/Business  Development 

Frank  S.  Genovese  •  973  244-5500,  ext.  19 

Regional  Manager/Consumer  Ad  Sales 

Pauline  Smith  •  508  988-6821 

Senior  Regional  Managers/Advertising  Sales 

Eileen  P.  Lobaugh  •  973  244-5500,  ext.  18 
Kathy  Powers  •  973  244-5500,  ext.  14 

Senior  Account  Executive 

Ellie  Schwab  •  973  244-5500,  ext.  16 

Senior  Sales  Associates 

Joan  Bonadeo  •  973  244-5500,  ext.  17 

Office  Manager 

Marlene  Levis  •  973  244-5500,  ext.  15 

Advertising  Sales  Associate 

Angela  Fung  •  973  244-5500,  Fax  973  227-1565 

New  England 

Senior  Regional  Manager/ Advertising  Sales 

Len  Ganz  •  508  935-4039 

Advertising  Sales  Assistant 

Dawn  Cora  •  508  935-4092,  Fax  508  872-0618 

Mid-Atlantic 

Regional  Manager/Advertising  Sales 

Louise  Cupelli 

Sales  Assistant  Vivek  Parmar 
215  627-8114.  Fax  215  627-8224 

South  Central 

Regional  Director/Advertising  Sales 

Robert  E.  Sawdon  •  512  306-9801,  Fax  512  306-9805 

North  Central 

Senior  Regional  Manager/ Advertising  Sales 

Keith  H.  Kenner 

Senior  Sales  Associate  Anne  Swartz 
847  441-5005,  Fax  847  441-5150 

West  Coast 

Regional  Director/ Advertising  Sales 

Richard  Bastas  •  415  693-1988 

Senior  Regional  Managers/Advertising  Sales 

James  Barrett  •  415  693-1995 
Paula  J.  Connor  •  415  693-5634 

Senior  Account  Executive 

Lucia  Bravo  •  415  693-5583 

Advertising  Sales  Associates 

Allison  Pierce  •  415  693-5630 


Sarajane  Robinson-Retondo 
415  693-1993,  Fax  415  398-4649 

Southern  California 

Senior  Regional  Manager/ Advertising  Sales 

Nancy  A.  Coy 

Account  Executive 

Chris  Bramel 

Senior  Sales  Associate 

Janis  Wikander  •  949  475-5579,  Fax  949  475-5583 

LIST  SERVICES 

List  Services  Manager 

Kathryn  A.W.  Grayson  •  508  935-4072 

List  Services  Account  Executive 

Stephanie  Roy  •  508  935-4151 

List  Services  Coordinator 

Kim  Cormican  •  508  935-4152 


CIO  is  published  in  the  United  States  as  well  as  in 
Australia,  CIO  Australia 

P.O.  Box  295,  St.  Leonards,  NSW  2065,  Australia 
61-2-9439-5133;  www.idg.com.au 

Canada,  CIO  Canada  (monthly) 

CIO  Enterprise  Canada  (biweekly) 

Laurentian  Technomedia  Inc.,  55  Town  Centre  Ct. 
Suite  302,  Scarborough,  M1P  4X4,  Ontario,  Canada 
416-290-0240;  www.lti.on.ca/cio 

China,  CEO&CIO  China 
China  Computerworld  Publishing 
Building  3,  4th  Floor 
16  Cuiweizhongli,  Wanshou  Rd. 

Beijing  10036,  China 
8610-6825-9416;  www.ceocio.com.cn 

India,  CIO  India 

Technology  Media  Group  Pvt.  Ltd. 

3540  HAL  2nd  Stage 

Indiranagar,  Bangalore,  India  560  038 

91-80-530-0309 

Korea,  CIO  Korea 

39,  Dangsan-Dong  1-Ga,  Youngdeungpo-Gu 
Seoul,  150-041,  Korea 
82-2-632-7561;  www.cio.seoul.kr 

New  Zealand,  CIO  New  Zealand 
P.O.  Box  6813,  Wellesley  St. 

Auckland  1036,  New  Zealand 
64-9-377-9902;  www.idg.co.nz 

IDG  is  the  world's  leading  IT  media,  research  and 
exposition  company.  Founded  in  1964,  IDG  had  1999 
revenues  of  $2.56  billion  and  has  more  than  12,000 
employees  worldwide.  IDG  offers  the  widest  range  of 
media  options,  which  reach  90  million  IT  buyers  in 
80  countries  representing  95  percent  of  worldwide 
IT  spending.  IDG's  diverse  product  and  services 


ONLINE  SERVICES 

VP/Online  Sales  Lisa  Brown  •  508  935-4470 

Online  Account  Executive  Michael  McPhee 
508  935-4611 

CUSTOM  PUBLISHING 

Director  Mary  Gregory 

Senior  Project  Manager  Nancy  O’Connell 
Project  Managers  Lisa  Chaffin,  Sally  Ellison 

Senior  Production  Editor  Chris  Brown 

REPRINT  SERVICES 

RMS  717  399-1900,  ext.  131 


For  further  sales  information,  visit 
www.cio.com/marketing/salesoffices.html. 


portfolio  spans  six  key  areas  including  print  publish¬ 
ing,  online  publishing,  expositions  and  conferences, 
market  research,  education  and  training,  and  global 
marketing  services.  More  than  90  million  people 
read  one  or  more  of  IDG's  290  magazines  and 
newspapers,  including  IDG’s  leading  global  brands— 
Computerworld,  PC  World,  Network  World, 

Macworld,  CIO  and  the  Channel  World  family  of 
publications.  IDG  Books  Worldwide  is  the  fastest- 
growing  computer  book  publisher  in  the  world,  with 
more  than  700  titles  in  38  languages.  The  "...For 
Dummies"  series  alone  has  more  than  75  million 
copies  in  print.  IDG  offers  online  users  the  largest 
network  of  technology-specific  websites  around  the 
world  through  IDG.net  ( www.idg.net ),  which  com¬ 
prises  more  than  250  targeted  websites  in  55  coun¬ 
tries  worldwide.  International  Data  Corporation 
(IDC)  is  the  world's  leading  provider  of  information 
technology  data,  analysis  and  consulting,  with 
research  centers  in  42  countries  and  more  than  575 
research  analysts  worldwide.  IDG  World  Expo  is  a 
leading  producer  of  more  than  168  globally  branded 
conferences  and  expositions  in  35  countries  includ¬ 
ing  E3  (Electronic  Entertainment  Expo),  Macworld 
Expo,  ComNet,  Windows  World  Expo,  ICE  (Internet 
Commerce  Expo),  Agenda,  DEMO  and  Spotlight. 
IDG's  training  subsidiary,  ExecuTrain,  is  the  world's 
largest  computer  training  company,  with  more  than 
250  locations  worldwide  and  785  training  courses. 
IDG  Marketing  Services  helps  industry-leading  IT 
companies  build  international  brand  recognition  by 
developing  globally  integrated  marketing  programs 
via  IDG's  print,  online  and  exposition  products 
worldwide.  Further  information  about  the  company 
can  be  found  at  www.idg.com. 


www.cio.com 


JUNE  1,  2000  CIO 


1  9  7 


Index  of  Companies  and  Advertisers 


Page  numbers  refer  to  the  first  page  of  the  article(s) 
in  which  the  company  is  mentioned.  This  index  is 
provided  as  a  service  to  readers.  The  publisher  does 
not  assume  any  liability  for  errors  or  omissions. 


Company  Index 

@Stake  Inc . 72 

Actiontec  Technologies  .  .164 

A-dec  Inc . 86 

Akamai  Technologies  Inc.  130 
Allied  Waste 

Industries  Inc . 86 

American  Home 

Products  Corp . 140 

AMR  Research  Inc . 86 

AT&T  Corp . 30 

Audiohighway  . 98 

Baan  Company  NV  . 86 

Backgrounds  Online  Inc.  .  .30 

BellSouth  Corp . 30 

Benchmarking 

Partners  Inc . 86 

Boston  Consulting 

Group  Inc.,  The . 30 

British  Telecom  AG  . 30 

Broadview  International 

LLC . 98 

CIMI  Corp . 130 

Cisco  Systems  Inc . 130 

Citrix  Corp . 120 

Cognos  Inc . 164 

Computer  Associates 


International  Inc.  .  .140,  164 
Computer  Economics  Inc.  164 


Computer.com . 98 

Cyberian  Outpost  Inc . 98 

DA  Consulting  Group  Inc.  .86 
Deutsche  Banc  Alex- 

Brown  . 130 

Diagonal  PLC . 86 

DMR  Consulting  Inc . 120 

eBay  Inc . 186 

Elf  Atochem  North 

America  Inc . 30 

EMC  Corp . 30 

Ernex  Marketing 

Technologies  Inc . 164 

Ernst  &  Young  LLP . 72 

Exodus 

Communications  Inc.  .  .130 

Fiduciary  Trust . 72 

Forrester  Research  Inc.  .  .164 

Foxwood  Casinos . 186 

FuelSpot.com  Inc . 30 

Gartner  Group  Inc.  .  .120, 140 

Global  Market . 164 

Granville  PLC . 86 

Harris  Corp . 164 

Hershey  Foods  Corp . 86 

Hewlett-Packard  Co . 140 


IBM  Corp.  .  .  .30,  72,  156, 164 


IBM  Global  Services . 72 

IBM  Research . 164 

icPIanet  Corp . 164 

Image  Info  Software  Inc.  .164 

Implementation  Management 

Associates  Inc . 86 

Indus  Corp . 152 

Informix  Corp . 130 

Intel  Corp . 30 

Interactive  Digital  Corp.  .  .  .30 

International  Data 

Corp . 86,  140 

IronPlanet  Inc . 30 

Janus  Technologies  Inc.  .  .140 
Jaws  Technologies  Inc.  .  .  .72 

Juran  Institute  Inc . 86 

KBKids.com  Inc . 120 

Keen.com  Inc . 30 

Kennedy  Information  LLC  .52 
Kleiner,  Perkins,  Caufield  & 

Byers  . 98 

Learning  Co.,  The . 130 

Lockheed  Martin  Corp.  .  .  .30 
LOpht  Heavy  Industries  .  .  .72 

Lycos  Inc . 130 

MainControl  Inc . 140 

Marriott  International  Inc.  140 

Mattel  Inc . 130 

Mercata  Inc . 186 

Meta  Group  Inc . 86, 130 

Microsoft  Corp . 

. 98,  120,  130, 140,  156 

Monsanto  Co . 86 

Netscape  Communications 

Corp . 186 

NetScreen  Technologies 

Inc . 164 

Network  Associates  Inc.  .  .164 
Network  Securities 

Technologies  Inc . 72 

OnLinkTechnologies  Inc.  .120 

Oracle  Corp . 30 

Para-Protect  Services  Inc.  .72 

PeopleSoft  Inc . 86, 140 

Peregrine  Systems  Inc.  .  .140 
PricewaterhouseCoopers 

LLP . 72,  86 

Purina  Mills  Inc . 86 

Sagent  Technology  Inc.  .  .  .98 

SAP  AG  . 86 

Searchbutton.com  . 164 

Sears,  Roebuck  and  Co.  .  .140 

Snap-on  Inc . 120 

Solutia  Inc . 86 


Springs  Industries  Inc . 30 

StorageNetworks  Inc . 130 

Sun  Microsystems  Inc.  .  .  .156 

Symantec  Corp . 164 

Tally  Systems  Corp . 140 

Tangram  Enterprise 

Solutions  Inc . 140 

Technologic  Partners . 98 

Tennessee  Valley 

Authority . 152 

Tibco  Software  Corp . 120 

Tivoli  Systems  Inc . 140 

Tradeum  Inc . 98 

USA  Group  Inc . 164 

Veritas  Software . 164 

VersusLaw  Inc . 30 

VerticalNet  Inc . 98 

Wal-Mart  Corp . 30 

WebMethods  Inc . 98 

Whirlpool  Corp . 86 

Williams  Communications 

Group  Inc . 140 

Winter  Corp . 30 

W.L.  Gore  &  Associates 

Inc . 86 

World  Kitchen  Inc . 86 

W.W.  Grainger  Inc . 86 

Xenote  Corp . 30 

Advertiser  Index 

Agilent  Technologies  . 77 

Ajilon  . 97 

Alcatel  USA  Inc . 49 

American  Power 

Conversion  . 64 

Arc  Plan  Inc . 149 

Argus  Systems  Group  ...  .50 

Attachmate  Corp . 39 

Avcom  . 135 

Bow  Street  Software  .  .  .  .103 

Cerebellum  Software . 83 

Check  Point  Software  .  .  .  .147 

Chordiant  Software . 173 

CIO  Communications  Inc.  .  .  . 

. 137,  169,  169A 

Comdisco  Inc . 151 

Compaq  Computer  Corp.  .  .2 
Computer  Associates 

Inti.  Inc . 7,  78 

Computerworld  . 162 

Concord  Communications  .  .8 
Content  Technologies  ...  .35 

Corio  Inc . 11 

Cylink  Corp . 63 

Datum  Inc . 167 

Dell  Computer  Corp . 165 

Digex  . 187 

Eprise  Corp . 58 

Ernst  &  Young  . 137A 

eXcelon  . 85 

FutureLink  . 28 


GTE  Corp . 177, 199 

Hewlett-Packard  Co . 12 

HNC  . 115 

IBM  Corp.  .  .  .67,  69,  70, 109, 
139, 193 

Infinium  Software  . C3 

Informix  Software  Inc . 42 

Intel  Corp . 36 

Intentia  . 95 

Intermedia 

Communications . 19 

Intraspect  Software  . 123 

I  planet  . 159 

Kana  Communications  ...  .61 

Kingston  Technology . C4 

Liebert  Corp . 129 

Lucent  Technologies  . 4 

MCI  Communications 

Corp . 16 

Mentor  Labs  . 117 

Microsoft  Corp . 45 

NEC  . 127 

net-HOPPER 

Systems  Inc . 101 

Network  Associates . C2 

Network  Engines . 161 

Network  Ice . 89 

New  Horizons  Computer 

Learning  Centers  . 25 

Novell . 93 

Oracle  Corp . 15 

Orderfusion  . 53 

Osprey  Systems . 185 

PC  Expo . 189 

PeopleSoft  Inc . 47 

PrivaSeek . 175 

Qwest . 155 

Research  In  Motion . 20 

Royalblue  Technologies  .  .119 

RSW . 145 

SAGA  Software  Inc . 191 

SAS  Institute  Inc . 31,  181 

Satyam . 133 

Secure  Computing 

Corp . Ill 

SecureLogix  Corp . 143 

Segue  Software  Inc . 183 

siteROCK . 33 

SiteSmith . 41 

Stonebridge 

Technologies . 91 

Technical  Resource 

Connection . 57 

Telemate.net  Software  .  .  .107 

Unisys  Corp . 23 

Veritas  Software . 27 

Viatel  . 179 

Webvision  Inc . 171 

Work  Management 
Solutions . 55 


Editorial,  Advertising  and 
Business  Offices:  492  Old 

Connecticut  Path,  P.O.  Box 
9208,  Framingham, 
Massachusetts  01701-9208, 
508  872-0080. 

Postal  Information:  CIO 

(ISSN  0894-9301)  is  pub¬ 
lished  semimonthly  and  as  a 
combined  issue  December 
15/January  1  by  CIO 
Communications  Inc.,  492 
Old  Connecticut  Path,  P.O. 
Box  9208,  Framingham, 
Massachusetts  01701-9208. 
Periodicals  postage  paid  at 
Framingham,  MA,  and  at 
additional  mailing  offices. 

Reprints:  Copyright  2000  by 
CIO  Communications  Inc.  All 
rights  reserved.  Reproduction 
of  material  appearing  in  CIO 
is  forbidden  without  written 
permission.  For  reprint 
requests,  contact  Reprint 
Management  Services  at  717 
399-1900  ext.  131  or  e-mail 
jeffm@rmsreprints.com. 

Photocopy  Rights: 

Permission  to  photocopy  for 
internal  or  personal  use  or 
the  internal  or  personal  use 
of  specific  clients  is  granted 
by  CIO  for  users  through  the 
Copyright  Clearance  Center 
(CCC),  provided  that  the 
base  fee  of  $3.00  per  copy 
of  the  article,  plus  $.50  per 
page  is  paid  directly  to 
Copyright  Clearance  Center, 
27  Congress  Street,  Salem, 
Massachusetts  01970.  Please 
specify:  ISSN  0894-9301. 
Permission  to  photocopy 
does  not  extend  to  con¬ 
tributed  articles  followed  by 
this  symbol:  $. 

Subscriptions:  Address 
inquiries  to  CIO,  492  Old 
Connecticut  Path,  P.O.  Box 
9208,  Framingham, 
Massachusetts  01701-9208; 
800  788-4605.  CIO  is  free  to 
qualified  information  execu¬ 
tives.  To  all  others  the  one- 
year  basic  rate  is  $89  for 
U.S.  and  Canada,  $125  to 
foreign  countries  (payable  in 
U.S.  funds  only).  The  single 
copy  price  is  $8.  Please 
allow  4  to  6  weeks  for  new 
subscriptions  to  begin. 

Change  of  Address:  Please 
fax  a  copy  of  current  sub¬ 
scription  label  along  with 
new  address  to  508  879- 
7899.  Allow  4  to  6  weeks  for 
change  to  take  effect. 

Postmaster:  Send  change  of 
address  to  CIO,  P.O.  Box 
489,  Northbrook,  Illinois 
60065-9816.  Printed  in  the 
U.S. A. 


19  8  CIO  JUNE  1,  2000 


www.c/o.com 


You’ve  been  waiting  for  someone  to  act  like  a  partner,  not  a  vendor. 


You’ve  been  waiting  for  an  Internet  that  lives  up  to  its  potential. 


You’ve  been  waiting  for  an  e-business  approach  that’s  complete  and  fully  integrated. 


You've  been  waiting  for  someone  to  help  reduce  time  to  market. 


You’ve  been  waiting  for  a  way  to  simplify  e-business  infrastructure. 


You’ve  been  waiting  for  someone  that  can  make  your  life  easier. 


You’ve  been  waiting  for  a  partner  that  solves  your  problems  rather  than  pushes  their  products. 


You’ve  been  waiting  for  someone  who  won't  disappear  once  they  install. 


You've  been  waiting  for  solutions  that  won’t  become  obsolete  the  second  your  company  grows. 


The  wait  is  over.  Genuity  is  here. 


b  u  $  in  CvS  s 
Mat  to  r  m  s 


GTE  Internetworking  is  now  called  Genuity.  And  Genuity  is  a  new  kind  of  partner.  One 
with  a  fully  integrated  approach.  With  people  who  understand  what  you  want  to  do,  where 
you  want  to  go  and  how  to  get  you  there.  Yesterday,  you  knew  us  as  GTE  Internetworking 
and  BBN,  the  firm  that  originally  brought  you  the  Internet.  From  now  on,  you’ll  know  us 
as  Genuity,  an  e-business  solutions  provider  that  understands  how  to  realize  your  vision. 


www.genuity.com  1-800-GENUITY 


GENUITY 


Proud  underwriter  of  CIO  Magazine  s  Enterprise  Value  Awards 


©Copyright  2000  Genuity. 


What  are  the  demands  of  being  both  a  CIO  and 
a  professor? 

People  say,  somewhat  jokingly,  that  I  have 
the  worst  job  here.  As  CIO  you  can  never 
satisfy  the  various  constituencies  you  serve 
because  the  minute  you  give  them  what 
they  want,  they  want  more.  My  academic 
background  is  a  particular  strength  in  the 
role  of  CIO  in  an  academic  institution. 
Some  CIOs  who  come  up  through  the 
technical  ranks  have  difficulty  at  the  high¬ 
est  level  because  they  have  never  had  an 
overview  of  the  whole  business.  Having 
been  a  faculty  member,  a  dean  and  an  aca¬ 
demic  administrator,  I  can  see  the  academic 
institution  from  all  perspectives.  I  teach 
because  I  love  it — teaching  keeps  me  on 
my  toes.  By  teaching  I  am  able  to  get  out 
with  the  students  and  touch  base  with 
other  faculty  and  hear  what  they  are  all 
doing.  It  is  such  a  good  reminder  of  why  I 


am  trying  to  do  what  I  am  doing  as  an 
administrator. 

Are  your  students  and  staff  tempted  to  drop  out 
and  take  jobs  in  this  hot  IT  market? 

Yes,  particularly  out  of  undergrad  computer 
science.  The  undergrads  are  dropping  out 
after  two  years.  I  am  also  seeing  that  in  my 
staff.  And  it’s  not  just  the  money.  Another 
piece  is  the  IT  environment.  Academe  used 
to  be  focused  on  cool  new  technology.  Now, 
we  have  this  core  underpinning  of  a  whole 
business,  and  the  technology  is  running  the 
enterprise  24  hours  a  day.  There  are  chal¬ 
lenges  but  it  is  basically  routine  and  it  takes  a 
different  mind-set  than  when  your  aim  is 
developing  the  latest,  coolest  thing.  HE! 


How  do  you  keep  on  the  pulse  of  your  constituents? 
Send  e-mail  to  Senior  Editor  Cheryl  Bentsen  at 
cbentsen@cio.com. 


Interview 

BY  CHERYL  BENTSEN 


Jose-Marie  Griffiths  is  CIO  for  the  Uni¬ 
versity  of  Michigan  and  a  professor  in  the 
graduate  School  of  Information,  where  stu¬ 
dents  prepare  for  careers  as  webmasters, 
CIOs,  librarians,  information  economists, 
digital  preservationists,  consultants  and  soft¬ 
ware  engineers.  The  British-born  Griffiths 
has  tackled  IT  projects  for  the  U.S.  Depart¬ 
ment  of  Energy,  the  IRS,  Unesco,  the 
National  Science  Foundation,  the  National 
Institutes  of  Health,  Lucent  Technologies’ 
Bell  Labs  and  the  British  Library. 


CIO:  The  School  of  Information  replaced  tradi¬ 
tional  library  studies.  What  is  the  librarian’s  role 
in  the  digital  age? 

GRIFFITHS:  Library  science  has  changed  dra¬ 
matically,  but  the  core  role  of  the  librarian — 
evaluating  knowledge  resources — remains 
unchanged.  People  assume  that  since  we  have 
the  web,  everybody  can  do  it  all  themselves. 
But  most  professionals  don’t  have  the  time. 
The  web  is  not  a  library.  Most  people  have  no 
idea  how  search  engines  work  and  don’t 
know  anything  about  the  quality  or  integrity 
of  the  information  they  are  accessing. 


200  CIO  JUNE  1,  2000  •  www.cio.com 


PHOTO  BY  KERRY  BOWMAN 


Weren’t  you  an  executive  when 
you  walked  in  this  morning? 


Our  guess  is  that  you’d  prefer  to  focus  on  your  core  business. To  get  you  there,  Infinium  ASP  offers  a  comprehensive  suite  of  business  software 
and  analytical  tools  that  are:  1.  available  over  the  Web,  2.  customized  to  your  business  processes,  3.  securely  hosted,  and  4.  able  to  support 
complex,  large-scale  businesses  as  well  as  start-ups.  Why  Infinium?  We’re  the  first  single-source,  fully  accountable  Application  Service  Provider, 
with  a  proven  track  record  of  delivering  solutions  to  2,000  customers.  For  a  copy  of  our  Executive  Report  on  the  business  benefits  of  ASPs, 
call  1 .877.356.0228,  or  go  to  infinium.com/asp. 


INFINIUM 

do  great  work 


www. kingston.com/jump/reliable 


JHSSTOH 


RVER  MEMORY. 


FEW  THINGS  IN  LIFE  ARE  GUARANTEED.  So  when  you  find  something  that  is,  you  stick  with  it.  That’s  why 
more  Fortune  500®companies  standardizeon  Kingston® server  memory  than  any  other  memory  brand.  Because  Kingston 
guarantees  reliability  with  every  module  it  ships.  How?  By  subjecting  each  module  to  the  most  rigorous  testing  in  the 
industry.  By  promising  the  highest  server  uptime  available.  And  by  certifying  100%  compatibility  with  the  system  or 
class  of  systems  it  was  designed  for.  Add  free  technical  support,  and  a  lifetime  warranty,  and  you’ve  got  memory 
guaranteed  to  get  you  through  a  lifetime  of  sunsets.  Don’t  wait  until  tomorrow.  Get  the  industry’s  most  reliable  memory  today. 
Go  to  www.kingston.com/jump/reliable  and  register  to  receive  your  free  Kingston  server  guide.  Or  call  (888)  435-5169. 


Kingston' 

!  JLm.T  E  C  H^N  O  L  O  G  Y 


Computing  Without  Limits* 


Kingston  Technology  Company,  Inc.  17600  Newhope  Street,  Fountain  Valley,  CA  92708  USA,  (714)  435-2600,  Fax  (714)  435-2699. 

©2000  Kingston  Technology  Company,  Inc.  All  rights  reserved.  All  other  trademarks  and  registered  trademarks  are  the  property  of  their  respective  owners. 


